peter bassill · operator
$ cve CVE-2009-4670 JSON

CVE-2009-4670 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 82)

Patch early

A public exploit exists.

Description

admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user parameter or (2) delete arbitrary rooms via the room parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.25% — more likely to be exploited than 82% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2010-03-05
Last modified2026-06-16

Affected (1)

VendorProduct
beaussierroomphplanning

Public exploits

SourceTitleDate
exploit-dbroomphplanning 1.6 - Multiple Vulnerabilities2009-05-26

References

→ the Explorer  ·  watch your stack  ·  NVD