CyberSec.Space Logo
Back to CVE Browser

CVE-2009-4929

HIGH
7.5
CVSS Severity Score
EPSS Score0.1660%
EPSS Percentile26.72th
PublishedJul 12, 2010
Last ModifiedApr 29, 2026

Vulnerability Description

admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwords via the newPW1 and newPW2 parameters.

Affected Platforms (CPE)

πŸ“¦
Sweetphp

Totalcalender

= 2.4

References & Advisories

Related Vulnerabilities