Unrated severityNVD Advisory· Published May 15, 2009· Updated Apr 23, 2026
CVE-2009-1637
CVE-2009-1637
Description
profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address and password via the email and password parameters.
Affected products
1- cpe:2.3:a:simplecustomer:simple_customer:1.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.