Filtered by vendor Kreado
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-44581 | 1 Kreado | 1 Kreasfero | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter. | |||||
CVE-2021-42675 | 1 Kreado | 1 Kreasfero | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution. |