PT-2007-2135 · Extcalendar · Extcalendar

Ajann

·

Published

2007-02-03

·

Updated

2024-02-09

·

CVE-2007-0681

CVSS v2.0
7.5
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P

Name of the Vulnerable Software and Affected Versions:

ExtCalendar versions 2 and earlier

Description:

The issue allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to "register.php".

Recommendations:

For ExtCalendar versions 2 and earlier, consider disabling the password change functionality in "profile.php" until a patch is available. Restrict access to "register.php" to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2007-0681

Affected Products

Extcalendar