CVE-2009-2040

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
12/06/2009
Last modified:
09/04/2025

Description

admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative accounts via a manage_admin action in a direct request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:grestul:grestul:1.2:*:*:*:*:*:*:*