PT-2023-25444 · Phpjabbers · Phpjabbers Class Scheduling System
CVE-2023-36134
·
Publicado
2023-08-03
·
Atualizado
2023-08-08
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PHP Jabbers Class Scheduling System version 1.0
Description
The issue concerns a lack of verification when changing an email address and/or password on the Profile Page, allowing remote attackers to take over accounts.
Recommendations
For PHP Jabbers Class Scheduling System version 1.0, consider implementing proper verification mechanisms for email address and password changes on the Profile Page to prevent unauthorized account takeovers. As a temporary workaround, restrict access to the Profile Page until a proper fix is implemented.
Exploit
Correção
Insufficient Verification of Data Authenticity
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Phpjabbers Class Scheduling System