
Proof-of-concept exploit for CVE-2023-34732 demonstrating authenticated function abuse in Flytxt NEON-dX to brute-force and reset user passwords, enabling account takeover.
An attacker can brute-force any user's password (including admins) using the userId parameter in the change password functionality and update the user's password to a new one chosen by the attacker.
Attack Type
Affected Versions
Vendor of Product
Affected Product Code Base
Affected Component
Mitigations
Vulnerability Details
Fixed versions
Discoverer