Vulnerabilities (CVE)

Filtered by vendor Ovidentia Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-22914 1 Ovidentia 1 Ovidentia 2022-02-25 5.0 MEDIUM 7.5 HIGH
An incorrect access control issue in the component FileManager of Ovidentia CMS 6.0 allows authenticated attackers to to view and download content in the upload directory via path traversal.
CVE-2019-13978 1 Ovidentia 1 Ovidentia 2019-07-27 6.5 MEDIUM 8.8 HIGH
Ovidentia 8.4.3 has SQL Injection via the id parameter in an index.php?tg=delegat&idx=mem request.
CVE-2018-1000619 1 Ovidentia 1 Ovidentia 2018-09-11 6.5 MEDIUM 8.8 HIGH
Ovidentia version 8.4.3 and earlier contains a Unsanitized User Input vulnerability in utilit.php, bab_getAddonFilePathfromTg that can result in Authenticated Remote Code Execution. This attack appear to be exploitable via The attacker must have permission to upload addons.