PT-2023-25444 · Phpjabbers · Phpjabbers Class Scheduling System

CVE-2023-36134

·

Publicado

2023-08-03

·

Atualizado

2023-08-08

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP Jabbers Class Scheduling System version 1.0
Description The issue concerns a lack of verification when changing an email address and/or password on the Profile Page, allowing remote attackers to take over accounts.
Recommendations For PHP Jabbers Class Scheduling System version 1.0, consider implementing proper verification mechanisms for email address and password changes on the Profile Page to prevent unauthorized account takeovers. As a temporary workaround, restrict access to the Profile Page until a proper fix is implemented.

Exploit

Correção

Insufficient Verification of Data Authenticity

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-36134

Produtos afetados

Phpjabbers Class Scheduling System