Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwords via the newPW1 and newPW2 parameters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sweetphp TotalCalendar 'manage_users.php'远程密码修改漏洞
Vulnerability Description
TotalCalendar是一种基于Web的日程管理系统。 TotalCalendar 2.4版本中的admin/manage_users.php没有正确请求管理员认证,远程攻击者可以借助newPW1和newPW2参数修改任意的密码。
CVSS Information
N/A
Vulnerability Type
N/A