VYPR

facileManager

by WillyXJ

CVEs (2)

  • CVE-2024-24572MedJan 31, 2024
    risk 0.00cvss 6.5epss 0.01

    facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, the $_REQUEST global array was unsafely called inside an extract() function in admin-logs.php. The PHP file fm-init.php prevents arbitrary manipulation of $_SESSION via…

  • CVE-2024-24571MedJan 31, 2024
    risk 0.00cvss 5.4epss 0.00

    facileManager is a modular suite of web apps built with the sysadmin in mind. For the facileManager web application versions 4.5.0 and earlier, we have found that XSS was present in almost all of the input fields as there is insufficient input validation.