Home

Description

In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

PUBLISHED Reserved 2023-06-21 | Published 2023-08-03 | Updated 2024-10-17 | Assigner mitre

References

www.phpjabbers.com/class-scheduling-system

medium.com/...rabilities-in-php-jabbers-scripts-25af4afcadd4

www.phpjabbers.com/class-scheduling-system

medium.com/...rabilities-in-php-jabbers-scripts-25af4afcadd4

cve.org (CVE-2023-36134)

nvd.nist.gov (CVE-2023-36134)

Download JSON