Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-6524

Опубликовано: 25 мар. 2009
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cale_dunlap:openinvoice:*:beta:*:*:*:*:*:*
Версия до 0.90 (включая)

EPSS

Процентиль: 86%
0.0283
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-255

Связанные уязвимости

github
больше 3 лет назад

resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication.

EPSS

Процентиль: 86%
0.0283
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-255