Codiad

Codiad

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.09%
  • Veröffentlicht 22.03.2024 03:15:07
  • Zuletzt bearbeitet 28.05.2025 18:46:12

Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.

  • EPSS 0.29%
  • Veröffentlicht 21.02.2023 18:15:11
  • Zuletzt bearbeitet 21.11.2024 03:22:49

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function saveJSON of the file components/install/process.php. The manipulation of the argument data leads to in...

  • EPSS 0.23%
  • Veröffentlicht 27.01.2021 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:13:46

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, anot...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 25.08.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:02:25

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later. The vulnerability occurs because of improper sanitization of the folder's name $path variable in components/filemanager/class.f...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 24.08.2020 16:15:10
  • Zuletzt bearbeitet 21.11.2024 05:02:25

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only available to admin users and it isn't CSRF protected in co...

Exploit
  • EPSS 2.4%
  • Veröffentlicht 24.08.2020 16:15:10
  • Zuletzt bearbeitet 21.11.2024 05:02:25

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin privileges could use the plugin install feature to make the server request any URL via components/mar...

Exploit
  • EPSS 39%
  • Veröffentlicht 16.03.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 04:34:19

Codiad Web IDE through 2.8.4 allows PHP Code injection.

Exploit
  • EPSS 23.4%
  • Veröffentlicht 21.11.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:53

Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.

Exploit
  • EPSS 50.42%
  • Veröffentlicht 12.07.2018 16:29:06
  • Zuletzt bearbeitet 21.11.2024 03:48:26

Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.

Exploit
  • EPSS 0.2%
  • Veröffentlicht 17.11.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.