Vulnerabilities > Cuteflow

DATE CVE VULNERABILITY TITLE RISK
2009-08-25 CVE-2009-2960 Permissions, Privileges, and Access Controls vulnerability in Cuteflow 2.10.3/2.11.0C
CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote attackers to modify usernames and passwords via a direct request.
network
low complexity
cuteflow CWE-264
7.5