VYPR

ClickHeat

by ClickHeat

CVEs (2)

  • CVE-2008-5793Dec 31, 2008
    risk 0.04cvss epss 0.24

    Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b)…

  • CVE-2015-4659Jun 18, 2015
    risk 0.03cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a config action to index.php.