profile.php in ExtCalendar 2 and earlier allows remote...
High severity
Unreviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Feb 18, 2024
Description
Published by the National Vulnerability Database
Feb 3, 2007
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Feb 18, 2024
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.
References