CVE-2007-0681

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
03/02/2007
Last modified:
09/04/2025

Description

profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:extcalendar_project:extcalendar:*:*:*:*:*:*:*:* 2 (including)