vendor:
TotalCalendar
by:
ThE g0bL!N
5.5
CVSS
MEDIUM
Remote Password Change
CWE
Product Name: TotalCalendar
Affected Version From: 2.4
Affected Version To: 2.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Powered by: TotalCalendar 2.4 Remote Password Change
The TotalCalendar 2.4 web application allows remote attackers to change passwords via a crafted request.
Mitigation:
Implement strong authentication mechanisms and input validation to prevent unauthorized password changes.