HIGH
cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail addresses of arbitrary accounts via a modified membercookie parameter, a different vector than CVE-2006-4078
Published Dec 4, 2007
9.0
HIGHCVSS 2.0
EPSS 2.74%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.