First published: Thu Aug 03 2023(Updated: )
In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPJabbers Cleaning Business Software | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-36139 is critical with a CVSS score of 9.8.
CVE-2023-36139 allows remote attackers to take over user accounts in PHPJabbers Cleaning Business Software 1.0.
To fix CVE-2023-36139, PHPJabbers Cleaning Business Software should implement email address and password verification when changing them on the Profile Page.
You can find more information about CVE-2023-36139 on the reference links provided: https://medium.com/@bcksec/multiple-vulnerabilities-in-php-jabbers-scripts-25af4afcadd4 and https://www.phpjabbers.com/cleaning-business-software/
The CWE ID of CVE-2023-36139 is 345.