Phpabook ProjectCVEs & Vulnerabilities
2 CVEs affecting Phpabook Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
phpabook 2
CVE-2022-30352CRITICAL
phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script.
2 Jun 2022
9.8
CVSS
CVE-2020-8510CRITICAL
An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.
3 Feb 2020
9.8
CVSS
← PrevPage 1 / 1Next →