Description
ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary users via a modified uid variable to siteadmin/useredit.php. NOTE: this can be used to recover the password of the user by using the modified e-mail address in the email parameter to recoverpass.php.
Published: 2009-09-09
Score: 7.5 High
EPSS: 3.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2008-7147 ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary users via a modified uid variable to siteadmin/useredit.php. NOTE: this can be used to recover the password of the user by using the modified e-mail address in the email parameter to recoverpass.php.
History

No history.

Subscriptions

Clip-share Clipshare
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T11:56:14.469Z

Reserved: 2009-09-09T00:00:00.000Z

Link: CVE-2008-7188

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2009-09-09T17:30:01.187

Modified: 2025-04-09T00:30:58.490

Link: CVE-2008-7188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses