CVE-2008-6524

Cale Dunlap Openinvoice < 0.90 - Credentials Management

Title source: rule

Description

resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication.

Exploits (1)

exploitdb WORKING POC VERIFIED
by t0pP8uZz · perlwebappsphp
https://www.exploit-db.com/exploits/5466

Scores

EPSS 0.0315
EPSS Percentile 86.9%

Details

CWE
CWE-255
Status published
Products (1)
cale_dunlap/openinvoice < 0.90
Published Mar 25, 2009
Tracked Since Feb 18, 2026