CVE-2009-1637
Simple Customer 1.3 - Unauthenticated Admin Credential Change via profile.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1637. PoCs published by ahmadbady.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Simple Customer 1.3, allowing an attacker to change the admin password without proper authentication. The PoC provides a form that submits directly to the vulnerable endpoint.
Description
profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address and password via the email and password parameters.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in Simple Customer 1.3, allowing an attacker to change the admin password without proper authentication. The PoC provides a form that submits directly to the vulnerable endpoint.