VYPR

Konga

by Konga Project

CVEs (2)

  • CVE-2023-26987MedMay 1, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

  • CVE-2021-42192HigMay 4, 2022
    risk 0.01cvss 8.8epss 0.10

    Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.