CVE-2007-6547: Medium severity Runcms RunCMS vulnerability
Published Dec 28, 2007
·Updated
RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session.
Affected Software
1 affected component
Runcms RunCMS<=1.6
Remediation
Patch Available
Event History
Dec 28, 2007
CVE Published
12:46 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6547?
CVE-2007-6547 has a medium severity rating due to the potential for unauthorized password changes.
2
How do I fix CVE-2007-6547?
To fix CVE-2007-6547, upgrade to RunCMS version 1.6.1 or later which enforces old password verification.
3
Who is affected by CVE-2007-6547?
CVE-2007-6547 affects users of RunCMS versions prior to 1.6.1.
4
What type of attack does CVE-2007-6547 enable?
CVE-2007-6547 allows context-dependent attackers to change user passwords without entering the old password.
5
What are the potential impacts of CVE-2007-6547?
The potential impacts of CVE-2007-6547 include unauthorized access to user accounts and potential data breaches.