peter bassill · operator
$ cve CVE-2008-5221 JSON

CVE-2008-5221 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.5% (pctl 85)

Patch early

A public exploit exists.

Description

The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.55% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2008-11-25
Last modified2026-06-16

Affected (1)

VendorProduct
wportfoliowportfolio

Public exploits

SourceTitleDate
exploit-dbwPortfolio 0.3 - Admin Password Changing2008-11-20

References

→ the Explorer  ·  watch your stack  ·  NVD