CVE-2023-7159
- EPSS 0.11%
- Veröffentlicht 29.12.2023 07:15:11
- Zuletzt bearbeitet 21.11.2024 08:45:24
A vulnerability was found in gopeak MasterLab up to 3.3.10. It has been declared as critical. Affected by this vulnerability is the function add/update of the file app/ctrl/admin/User.php. The manipulation of the argument avatar leads to unrestricted...
CVE-2023-7147
- EPSS 0.17%
- Veröffentlicht 29.12.2023 03:15:11
- Zuletzt bearbeitet 21.11.2024 08:45:22
A vulnerability, which was classified as critical, was found in gopeak MasterLab up to 3.3.10. Affected is the function base64ImageContent of the file app/ctrl/User.php. The manipulation of the argument image leads to unrestricted upload. It is possi...
CVE-2023-7145
- EPSS 0.11%
- Veröffentlicht 29.12.2023 02:15:45
- Zuletzt bearbeitet 21.11.2024 08:45:22
A vulnerability classified as critical was found in gopeak MasterLab up to 3.3.10. This vulnerability affects the function sqlInject of the file app/ctrl/Framework.php of the component HTTP POST Request Handler. The manipulation of the argument pwd l...
CVE-2023-7146
- EPSS 0.11%
- Veröffentlicht 29.12.2023 02:15:45
- Zuletzt bearbeitet 21.11.2024 08:45:22
A vulnerability, which was classified as critical, has been found in gopeak MasterLab up to 3.3.10. This issue affects the function sqlInjectDelete of the file app/ctrl/framework/Feature.php of the component HTTP POST Request Handler. The manipulatio...
CVE-2023-7144
- EPSS 0.11%
- Veröffentlicht 29.12.2023 01:15:44
- Zuletzt bearbeitet 21.11.2024 08:45:22
A vulnerability classified as critical has been found in gopeak MasterLab up to 3.3.10. This affects the function sqlInject of the file app/ctrl/framework/Feature.php of the component HTTP POST Request Handler. The manipulation of the argument pwd le...
CVE-2020-23534
- EPSS 0.32%
- Veröffentlicht 25.02.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:13:51
A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.