Hybbs2
by Hyphp
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24677 | Cri | 0.64 | 9.8 | 0.02 | Feb 9, 2022 | Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php. | ||
| CVE-2022-24676 | Hig | 0.57 | 8.8 | 0.01 | Feb 9, 2022 | update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive. |
- risk 0.64cvss 9.8epss 0.02
Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.
- risk 0.57cvss 8.8epss 0.01
update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.