An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowing local authenticated attackers to escalate privileges to root.
https://gist.github.com/xbz0n/4b98e9291ddd5bb5e6232609e36b2082