VYPR

BuddyBoss

by Buddyboss

CVEs (2)

  • CVE-2023-32670CriOct 3, 2023
    risk 0.59cvss 9.0epss 0.00

    Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when…

  • CVE-2023-32669MedOct 3, 2023
    risk 0.35cvss 5.4epss 0.00

    Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other users' albums. This vulnerability can be exploited by changing the album identification (id).