Vulnerabilities (CVE)

Filtered by vendor Codiad Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-19423 1 Codiad 1 Codiad 2022-02-19 6.5 MEDIUM 7.2 HIGH
Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.
CVE-2020-23355 1 Codiad 1 Codiad 2021-07-21 4.3 MEDIUM 7.5 HIGH
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234 something can successfully authenticate.
CVE-2020-14043 1 Codiad 1 Codiad 2021-03-30 6.8 MEDIUM 8.8 HIGH
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only available to admin users and it isn't CSRF protected in components/market/controller.php. This might cause admins to make a vulnerable request without them knowing and result in remote code execution. NOTE: the vendor states "Codiad is no longer under active maintenance by core contributors."
CVE-2020-14044 1 Codiad 1 Codiad 2021-03-30 6.5 MEDIUM 7.2 HIGH
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin privileges could use the plugin install feature to make the server request any URL via components/market/class.market.php. This could potentially result in remote code execution. NOTE: the vendor states "Codiad is no longer under active maintenance by core contributors."
CVE-2017-1000125 1 Codiad 1 Codiad 2019-10-03 5.0 MEDIUM 7.5 HIGH
Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.