profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original…
mitre·CWE-522·Published 2007-02-03