Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:bedita:bedita:3.1.4:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2019-15570 |
BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters. Published: August 26, 2019; 11:15:12 AM -0400 |
V3.0: 9.8 CRITICAL V2.0: 7.5 HIGH |
CVE-2015-9260 |
An issue was discovered in BEdita before 3.7.0. A cross-site scripting (XSS) attack occurs via a crafted pages/showObjects URI, as demonstrated by appending a payload to a pages/showObjects/2/0/0/leafs URI. Published: July 04, 2018; 10:29:00 PM -0400 |
V3.1: 5.4 MEDIUM V2.0: 3.5 LOW |
CVE-2015-6809 |
Multiple cross-site scripting (XSS) vulnerabilities in BEdita before 3.6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cfg[projectName] parameter to index.php/admin/saveConfig, the (2) data[stats_provider_url] parameter to index.php/areas/saveArea, or the (3) data[description] parameter to index.php/areas/saveSection. Published: September 04, 2015; 11:59:06 AM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |