Lucene search

K
cvelistMitreCVELIST:CVE-2008-6524
HistoryMar 25, 2009 - 6:00 p.m.

CVE-2008-6524

2009-03-2518:00:00
mitre
www.cve.org
3

AI Score

6.3

Confidence

Low

EPSS

0.004

Percentile

73.3%

resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication.

AI Score

6.3

Confidence

Low

EPSS

0.004

Percentile

73.3%

Related for CVELIST:CVE-2008-6524