RSS   Vulnerabilities for 'Chevereto'   RSS

2021-06-30
 
CVE-2021-31721

CWE-79
 

 
Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.

 
2017-07-17
 
CVE-2017-1000058

 

 
Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser.

 
2012-05-21
 
CVE-2012-2919

CWE-22
 

 
Directory traversal vulnerability in Upload/engine.php in Chevereto 1.9.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the v parameter.

 
 
CVE-2012-2918

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in Upload/engine.php in Chevereto 1.91 allows remote attackers to inject arbitrary web script or HTML via the v parameter.

 


Copyright 2024, cxsecurity.com

 

Back to Top