CVE-2008-2488

Beaussier Roomphplanning - Access Control

Title source: rule

Description

admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin accounts.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stack · textwebappsphp
https://www.exploit-db.com/exploits/5674

Scores

EPSS 0.0439
EPSS Percentile 88.8%

Classification

CWE
CWE-264
Status draft

Affected Products (1)

beaussier/roomphplanning

Timeline

Published May 28, 2008
Tracked Since Feb 18, 2026