First published: Thu Aug 03 2023(Updated: )
In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPJabbers Class Scheduling System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36134 is a vulnerability in PHP Jabbers Class Scheduling System 1.0 that allows remote attackers to take over accounts by changing email addresses and/or passwords without verification.
CVE-2023-36134 has a severity rating of 9.8 (Critical).
PHP Jabbers Class Scheduling System 1.0 is affected by CVE-2023-36134.
To fix CVE-2023-36134, it is recommended to update to a patched version of PHP Jabbers Class Scheduling System or apply any available security patches or fixes provided by the vendor.
You can find more information about CVE-2023-36134 at the following links: [https://medium.com/@bcksec/multiple-vulnerabilities-in-php-jabbers-scripts-25af4afcadd4](https://medium.com/@bcksec/multiple-vulnerabilities-in-php-jabbers-scripts-25af4afcadd4) and [https://www.phpjabbers.com/class-scheduling-system](https://www.phpjabbers.com/class-scheduling-system).