Vulnerabilities (CVE)

Filtered by vendor Traq Subscribe
Filtered by product Traq
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20779 1 Traq 1 Traq 2023-12-10 7.5 HIGH 9.8 CRITICAL
Traq 3.7.1 allows SQL Injection via a tickets?search= URI.
CVE-2018-20780 1 Traq 1 Traq 2023-12-10 6.8 MEDIUM 8.8 HIGH
Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1).