PT-2008-3945 · Roomphplanning · Roomphplanning

Stack

·

Published

2008-05-28

·

Updated

2017-09-29

·

CVE-2008-2488

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: RoomPHPlanning version 1.5
Description: The issue allows remote authenticated users to create new admin accounts without requiring administrative credentials. This is due to a lack of proper authentication in the admin/userform.php file.
Recommendations: For RoomPHPlanning version 1.5, consider restricting access to the admin/userform.php file until a patch is available, or apply configuration changes to require administrative credentials for creating new admin accounts.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2488

Affected Products

Roomphplanning