Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5q7c-4cgc-gvcr

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

PunBB 1.2.9 does not require password entry when changing the e-mail address in an account's profile, which might allow an attacker to make an address change via a hijacked login session.

PunBB 1.2.9 does not require password entry when changing the e-mail address in an account's profile, which might allow an attacker to make an address change via a hijacked login session.

EPSS

Процентиль: 56%
0.00333
Низкий

Связанные уязвимости

nvd
около 20 лет назад

PunBB 1.2.9 does not require password entry when changing the e-mail address in an account's profile, which might allow an attacker to make an address change via a hijacked login session.

EPSS

Процентиль: 56%
0.00333
Низкий