CVE-2009-4670 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 82)
Patch early
A public exploit exists.
Description
admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user parameter or (2) delete arbitrary rooms via the room parameter.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.25% — more likely to be exploited than 82% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-03-05 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| beaussier | roomphplanning |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | roomphplanning 1.6 - Multiple Vulnerabilities | 2009-05-26 |
References
→ the Explorer · watch your stack · NVD