account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the My Account page.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Duclassmate | Duware | 1.0 (including) | 1.0 (including) |
| Duclassmate | Duware | 1.1 (including) | 1.1 (including) |