Vulnerabilities (CVE)

Filtered by vendor Kreado Subscribe
Filtered by product Kreasfero
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-44581 1 Kreado 1 Kreasfero 2023-12-10 5.0 MEDIUM 7.5 HIGH
An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter.
CVE-2021-42675 1 Kreado 1 Kreasfero 2023-12-10 7.5 HIGH 9.8 CRITICAL
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.