An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.
https://0xem.ma/cve/2020/01/31/CVE-2020-8510.html
https://sourceforge.net/p/phpabook/news/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8510