VYPR
Unrated severityNVD Advisory· Published May 15, 2009· Updated Apr 23, 2026

CVE-2009-1637

CVE-2009-1637

Description

profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address and password via the email and password parameters.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.