The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password parameters to index.php.Referenceshttps://www.htbridge.com/advisory/HTB23101http://www.pbboard.com/forums/t10353.htmlhttp://osvdb.org/84481http://www.securityfocus.com/bid/54916http://www.pbboard.com/forums/t10352.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/77506http://secunia.com/advisories/50153