PT-2008-3945 · Roomphplanning · Roomphplanning
Stack
·
Published
2008-05-28
·
Updated
2017-09-29
·
CVE-2008-2488
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
RoomPHPlanning version 1.5
Description:
The issue allows remote authenticated users to create new admin accounts without requiring administrative credentials. This is due to a lack of proper authentication in the admin/userform.php file.
Recommendations:
For RoomPHPlanning version 1.5, consider restricting access to the admin/userform.php file until a patch is available, or apply configuration changes to require administrative credentials for creating new admin accounts.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Roomphplanning