Geeklog v1.3.8 and below contains a SQL injection vulnerability allowing malicious users to change passwords on arbitrary users. Fix available here.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31863/geeklog-1.3.8.txt
Source: https://packetstormsecurity.com/files/31863/geeklog-1.3.8.txt.html

