peter bassill · operator
$ cve CVE-2007-5374 JSON

CVE-2007-5374 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 2.2% (pctl 82)

Patch early

A public exploit exists.

Description

cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticated users to increase the privileges of any account.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS2.19% — more likely to be exploited than 82% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2007-10-11
Last modified2026-06-16

Affected (1)

VendorProduct
lightbloglightblog

Public exploits

SourceTitleDate
exploit-dbLightBlog 8.4.1.1 - Remote Code Execution2007-10-09

References

→ the Explorer  ·  watch your stack  ·  NVD