CVE-2008-6524
Cale Dunlap Openinvoice < 0.90 - Credentials Management
Title source: ruleDescription
resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by t0pP8uZz · perlwebappsphp
https://www.exploit-db.com/exploits/5466
References (4)
Scores
EPSS
0.0315
EPSS Percentile
86.9%
Details
CWE
CWE-255
Status
published
Products (1)
cale_dunlap/openinvoice
< 0.90
Published
Mar 25, 2009
Tracked Since
Feb 18, 2026