Loading vulnerability details…
CVSS v3.1
N/A
EPSS
4.93%
Published
Nov 23, 2004
Modified
Jun 16, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another userID.
Affected Products (1)
References (12)