Layerbb
by Andyrixon
Source repositories
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-17997 | 0.03 | — | 0.02 | Mar 17, 2019 | LayerBB 1.1.1 allows XSS via the titles of conversations (PMs). | |||
| CVE-2018-17996 | 0.03 | — | 0.00 | Mar 17, 2019 | LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/. | |||
| CVE-2018-17988 | 0.00 | — | 0.00 | Mar 7, 2019 | LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter. |
- CVE-2018-17997Mar 17, 2019risk 0.03cvss —epss 0.02
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
- CVE-2018-17996Mar 17, 2019risk 0.03cvss —epss 0.00
LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/.
- CVE-2018-17988Mar 7, 2019risk 0.00cvss —epss 0.00
LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter.