SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-4637

xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspecified changes via an unknown series of steps.

MEDIUM 6.4EPSS 2.17%

Does this matter?

Lower severity and a low EPSS score (2.17%). Track it; it rarely justifies an emergency change on its own.

Description

xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspecified changes via an unknown series of steps.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS
2.17% probability · 81th percentile
CISA KEV
Not listed
Affected
xgb/xgb
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.