CVE-2009-1637
Simplecustomer Simple Customer - Access Control
Title source: ruleDescription
profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address and password via the email and password parameters.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by ahmadbady · htmlwebappsphp
https://www.exploit-db.com/exploits/8638
References (5)
Scores
EPSS
0.0347
EPSS Percentile
87.6%
Details
CWE
CWE-264
Status
published
Products (1)
simplecustomer/simple_customer
1.3
Published
May 15, 2009
Tracked Since
Feb 18, 2026