"value":"A CWE-862 \"Missing Authorization\" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to reset passwords, including the ones of administrator accounts, via crafted HTTP requests."
"value":"Un CWE-862 \"Autorizaci\u00f3n faltante\" en maxprofile/users/routes.lua en Q-Free MaxTime menor o igual a la versi\u00f3n 2.11.0 permite a un atacante autenticado (con pocos privilegios) restablecer contrase\u00f1as, incluida las de cuentas de administrador, a trav\u00e9s de solicitudes HTTP manipulado."