Elgg kayıtları
elgg üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %45,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2011-2936İstismar yok | Elgg through 1.7.10 has a SQL injection vulnerabilityelgg · elgg · CWE-89 | Kritik9,8 | — | %1,5 | 12 Kas 2019 |
30İzleyin | CVE-2021-3980İstismar yok | Exposure of Private Personal Information to an Unauthorized Actor in elgg/elggelgg · elgg · CWE-359 | Yüksek7,5 | — | %1,6 | 3 Ara 2021 |
27İzleyin | CVE-2012-6562İstismar yok | engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to creelgg · elgg · CWE-264 | Orta6,8 | — | %1,3 | 23 May 2013 |
24İzleyin | CVE-2019-11016İstismar yok | Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect.elgg · elgg · CWE-601 | Orta6,1 | — | %1,2 | 8 Nis 2019 |
24İzleyin | CVE-2011-2935İstismar yok | Elgg through 1.7.10 has XSSelgg · elgg · CWE-79 | Orta6,1 | — | %1,1 | 12 Kas 2019 |
23İzleyin | CVE-2021-3964İstismar yok | Authorization Bypass Through User-Controlled Key in elgg/elggelgg · elgg · CWE-639 | Orta5,9 | — | %0,8 | 1 Ara 2021 |
21İzleyin | CVE-2021-4072İstismar yok | Cross-site Scripting (XSS) - Stored in elgg/elggelgg · elgg · CWE-79 | Orta5,4 | — | %0,7 | 24 Ara 2021 |
20İzleyin | CVE-2011-3733İstismar yok | Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path elgg · elgg · CWE-200 | Orta5,0 | — | %1,3 | 23 Eyl 2011 |
17İzleyin | CVE-2013-0234İstismar yok | Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to injeelgg · elgg · CWE-79 | Orta4,3 | — | %1,5 | 2 Şub 2014 |
17İzleyin | CVE-2012-6563İstismar yok | engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to elgg · elgg · CWE-264 | Orta4,3 | — | %1,2 | 23 May 2013 |
17İzleyin | CVE-2012-6561İstismar yok | Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbitrary web scriptelgg · elgg · CWE-79 | Orta4,3 | — | %1,2 | 23 May 2013 |
- CVE-2011-293639İzleyin
Elgg through 1.7.10 has a SQL injection vulnerability
KritikCVSS 9,8İstismar yokEPSS %2elgg · elgg12 Kas 2019
- CVE-2021-398030İzleyin
Exposure of Private Personal Information to an Unauthorized Actor in elgg/elgg
YüksekCVSS 7,5İstismar yokEPSS %2elgg · elgg3 Ara 2021
- CVE-2012-656227İzleyin
engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to cre
OrtaCVSS 6,8İstismar yokEPSS %1elgg · elgg23 May 2013
- CVE-2019-1101624İzleyin
Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect.
OrtaCVSS 6,1İstismar yokEPSS %1elgg · elgg8 Nis 2019
- CVE-2011-293524İzleyin
Elgg through 1.7.10 has XSS
OrtaCVSS 6,1İstismar yokEPSS %1elgg · elgg12 Kas 2019
- CVE-2021-396423İzleyin
Authorization Bypass Through User-Controlled Key in elgg/elgg
OrtaCVSS 5,9İstismar yokEPSS %1elgg · elgg1 Ara 2021
- CVE-2021-407221İzleyin
Cross-site Scripting (XSS) - Stored in elgg/elgg
OrtaCVSS 5,4İstismar yokEPSS %1elgg · elgg24 Ara 2021
- CVE-2011-373320İzleyin
Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path
OrtaCVSS 5,0İstismar yokEPSS %1elgg · elgg23 Eyl 2011
- CVE-2013-023417İzleyin
Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inje
OrtaCVSS 4,3İstismar yokEPSS %1elgg · elgg2 Şub 2014
- CVE-2012-656317İzleyin
engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to
OrtaCVSS 4,3İstismar yokEPSS %1elgg · elgg23 May 2013
- CVE-2012-656117İzleyin
Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbitrary web script
OrtaCVSS 4,3İstismar yokEPSS %1elgg · elgg23 May 2013