A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file inc/mod/pages.php of the component Password Change Handler. The manipulation of the argument Password leads to unverified password change. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Mon, 16 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vichan-devel
Vichan-devel vichan |
|
| Vendors & Products |
Vichan-devel
Vichan-devel vichan |
Mon, 16 Feb 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file inc/mod/pages.php of the component Password Change Handler. The manipulation of the argument Password leads to unverified password change. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | vichan-devel vichan Password Change pages.php unverified password change | |
| Weaknesses | CWE-620 CWE-640 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-02-16T07:02:06.623Z
Updated: 2026-02-16T07:02:06.623Z
Reserved: 2026-02-15T15:51:48.549Z
Link: CVE-2026-2543
No data.
Status : Received
Published: 2026-02-16T07:17:01.007
Modified: 2026-02-16T07:17:01.007
Link: CVE-2026-2543
No data.