Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ExtCalendar'profile.php'密码问题漏洞
Vulnerability Description
ExtCalendar 2版本及其早期版本的profile.php允许远程攻击者可以借助对register.php的修改过的值,不用提供原密码就可以更改任意用户的密码并可能执行其他未验证操作。
CVSS Information
N/A
Vulnerability Type
N/A