CVE-2000-1228EPSS p83.9%

CVE-2000-1228CVE-2000-1228

phorum / phorum

Description

Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.

Scoring

CVSS 5.0 ()
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS2.46% probability of exploitation · percentile 83.9% · 2026-10-05T12:00:23Z
Last modified2026-09-23
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.