First published: Tue Aug 01 2023(Updated: )
In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPJabbers Time Slots Booking Calendar | =3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-33563 is high with a CVSS score of 8.8.
CVE-2023-33563 affects PHP Jabbers Time Slots Booking Calendar version 3.3.
The vulnerability in PHP Jabbers Time Slots Booking Calendar 3.3 is the lack of verification when changing an email address and/or password on the Profile Page.
An attacker can exploit CVE-2023-33563 by taking over user accounts in PHP Jabbers Time Slots Booking Calendar by changing the email address and/or password without proper verification.
Yes, you can find references for CVE-2023-33563 at the following links: [Medium article](https://medium.com/@bcksec/multiple-vulnerabilities-in-php-jabbers-scripts-25af4afcadd4) and [PHP Jabbers Time Slots Booking Calendar website](https://www.phpjabbers.com/time-slots-booking-calendar/).