SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-1780

admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.

HIGH 7.5EPSS 3.76%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.76%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
3.76% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-306
Affected
frax/php recommend
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.