CVE-2023-2759 — A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user to change passwords of other users without any prior knowledge. The attacker — CVE Database · The Intelligence Room