VYPR

Atals-Livre

by MaximeAmini

CVEs (2)

  • CVE-2026-69704Aug 4, 2026
    risk 0.00cvss epss

    Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion helper function. Attackers can inject malicious SQL syntax via the vulnerable GET parameter to…

  • CVE-2026-69703Aug 4, 2026
    risk 0.00cvss epss

    Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke…