CVE-2007-0681
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.20% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- extcalendar project/extcalendar
- Source
- cve@mitre.org
References
- http://osvdb.org/38130Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32035Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/3239Exploit, Third Party Advisory, VDB Entry
- http://osvdb.org/38130Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32035Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/3239Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.