First published: Fri Dec 28 2007(Updated: )
RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runcms Runcms | <=1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6547 has a medium severity rating due to the potential for unauthorized password changes.
To fix CVE-2007-6547, upgrade to RunCMS version 1.6.1 or later which enforces old password verification.
CVE-2007-6547 affects users of RunCMS versions prior to 1.6.1.
CVE-2007-6547 allows context-dependent attackers to change user passwords without entering the old password.
The potential impacts of CVE-2007-6547 include unauthorized access to user accounts and potential data breaches.