CVE-2017-8848by Jeremyin Security Bulletinson Posted on May 8, 2017 Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.