VYPR
Unrated severityNVD Advisory· Published Mar 5, 2010· Updated Jun 16, 2026

CVE-2009-4670

CVE-2009-4670

Description

admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user parameter or (2) delete arbitrary rooms via the room parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.