CVE-2009-1637

Simplecustomer Simple Customer - Access Control

Title source: rule

Description

profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address and password via the email and password parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ahmadbady · htmlwebappsphp
https://www.exploit-db.com/exploits/8638

Scores

EPSS 0.0347
EPSS Percentile 87.6%

Details

CWE
CWE-264
Status published
Products (1)
simplecustomer/simple_customer 1.3
Published May 15, 2009
Tracked Since Feb 18, 2026