In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HPhpjabbers Cleaning Business Software
APPPhpjabbers1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2023-36140CRITICAL9.8PL ✓same product
PHPJabbers Cleaning Business Software — brak szyfrowania haseł użytkowników
CVE-2023-51328MEDIUM5.4same product
PHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the ...
CVE-2023-51331MEDIUM6.5same product
PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attack...
CVE-2023-51326MEDIUM6.5same product
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows ...
CVE-2023-51327MEDIUM6.5same product
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows ...