VYPR

by Squiz

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-14198Hig0.578.80.01Nov 30, 2017An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) via a maliciously crafted time_format tag.
CVE-2017-14197Med0.406.10.00Nov 30, 2017An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. There are multiple reflected Cross-Site Scripting (XSS) issues in Matrix WYSIWYG plugins.