Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.062
EPSS Ranking 90.5%