7.5
CVSSv2

CVE-2009-2960

Published: 25/08/2009 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote malicious users to modify usernames and passwords via a direct request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cuteflow cuteflow 2.11.0_c

cuteflow cuteflow 2.10.3

Exploits

It's possible edit the users (including the admin account), bypassing the authentication through the address: localhost/cuteflow/pages/edituserphp?userid=1&language=pt&sortby=st rLastName&sortdir=ASC&start=1 The vulnerability is caused due to the application not properly restricting access to the pages/edituserphp script ...