Vulnerabilities (CVE)

Filtered by vendor Qibosoft Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-20944 1 Qibosoft 1 Qibosoft 2022-07-12 6.4 MEDIUM 9.1 CRITICAL
An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.
CVE-2019-17613 1 Qibosoft 1 Qibosoft 2019-10-18 7.5 HIGH 9.8 CRITICAL
qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as demonstrated by a payload in the content parameter.