CVE-2024-26557
- EPSS 0.09%
- Veröffentlicht 22.03.2024 03:15:07
- Zuletzt bearbeitet 28.05.2025 18:46:12
Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.
CVE-2017-20178
- EPSS 0.29%
- Veröffentlicht 21.02.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 03:22:49
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function saveJSON of the file components/install/process.php. The manipulation of the argument data leads to in...
CVE-2020-23355
- EPSS 0.23%
- Veröffentlicht 27.01.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:13:46
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, anot...
CVE-2020-14042
- EPSS 0.34%
- Veröffentlicht 25.08.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:02:25
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later. The vulnerability occurs because of improper sanitization of the folder's name $path variable in components/filemanager/class.f...
CVE-2020-14043
- EPSS 0.4%
- Veröffentlicht 24.08.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:25
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only available to admin users and it isn't CSRF protected in co...
CVE-2020-14044
- EPSS 2.4%
- Veröffentlicht 24.08.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:25
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin privileges could use the plugin install feature to make the server request any URL via components/mar...
CVE-2019-19208
- EPSS 39%
- Veröffentlicht 16.03.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:19
Codiad Web IDE through 2.8.4 allows PHP Code injection.
CVE-2018-19423
- EPSS 23.4%
- Veröffentlicht 21.11.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:53
Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.
- EPSS 50.42%
- Veröffentlicht 12.07.2018 16:29:06
- Zuletzt bearbeitet 21.11.2024 03:48:26
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
CVE-2017-1000125
- EPSS 0.2%
- Veröffentlicht 17.11.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.