vendor:
OpenInvoice
by:
t0pP8uZz
7.5
CVSS
HIGH
Arbitrary Change User Password
264
CWE
Product Name: OpenInvoice
Affected Version From: 0.9
Affected Version To: 0.9
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
OpenInvoice 0.9 Arbitrary Change User Password Exploit
OpenInvoice 0.9 beta (and prior) Suffers from Insecure cookies and admin panel validating, combining the two, an attacker can change any users password except for the 1st admin.
Mitigation:
Upgrade to the latest version of OpenInvoice