member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Discuz! | Discuz | - (including) | - (including) |