Vulnerabilities > Phpjabbers > Cleaning Business Software > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-09-11 CVE-2023-36140 Missing Authorization vulnerability in PHPjabbers Cleaning Business Software 1.0
In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.
network
low complexity
phpjabbers CWE-862
critical
9.8
2023-08-04 CVE-2023-36139 Insufficient Verification of Data Authenticity vulnerability in PHPjabbers Cleaning Business Software 1.0
In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
network
low complexity
phpjabbers CWE-345
critical
9.8