Member_ProfileForm in security/Member.php in SilverStripe 2.3.x before 2.3.7 allows remote attackers to hijack user accounts by saving data using the email address (ID) of another user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 72.3%