VYPR

Ushahidi_Web

by Ushahidi

Source repositories

CVEs (2)

  • CVE-2012-5618CriFeb 4, 2020
    risk 0.57cvss 9.8epss 0.01

    Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.

  • CVE-2012-3472Aug 12, 2012
    risk 0.00cvss epss 0.01

    The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows remote attackers to list, delete, or organize messages via a GET request.