CVE-2017-8848

Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.