Loading...
Loading...
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters.
November 25, 2008
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2008-5221
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.