Codiad
Products
1- 14 CVEs
Recent CVEs
14| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-14009 | Cri | 0.70 | 9.8 | 0.38 | Jul 12, 2018 | Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689. | ||
| CVE-2019-19208 | Cri | 0.68 | 9.8 | 0.19 | Mar 16, 2020 | Codiad Web IDE through 2.8.4 allows PHP Code injection. | ||
| CVE-2020-14043 | Hig | 0.57 | 8.8 | 0.02 | Aug 24, 2020 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only available to admin users and it isn't CSRF protected in… | ||
| CVE-2017-11366 | Cri | 0.57 | 9.8 | 0.08 | Aug 21, 2017 | components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demonstrated by search_file_type. | ||
| CVE-2018-19423 | Hig | 0.51 | 7.2 | 0.18 | Nov 21, 2018 | Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file. | ||
| CVE-2020-23355 | Hig | 0.49 | 7.5 | 0.01 | Jan 27, 2021 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234… | ||
| CVE-2017-1000125 | Hig | 0.49 | 7.5 | 0.01 | Nov 17, 2017 | Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell. | ||
| CVE-2020-14044 | Hig | 0.47 | 7.2 | 0.03 | Aug 24, 2020 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin privileges could use the plugin install feature to make the server request any URL via components/market/class.market.php. This… | ||
| CVE-2020-14042 | Med | 0.40 | 6.1 | 0.01 | Aug 25, 2020 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later. The vulnerability occurs because of improper sanitization of the folder's name $path variable in components/filemanager/class.filemanager.php. NOTE: the… | ||
| CVE-2024-26557 | Med | 0.35 | 5.4 | 0.00 | Mar 22, 2024 | Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter. | ||
| CVE-2017-20178 | Low | 0.13 | 3.1 | 0.01 | Feb 21, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function saveJSON of the file components/install/process.php. The manipulation of the argument data leads to information disclosure. The… | ||
| CVE-2014-9582 | 0.03 | — | 0.01 | Jan 8, 2015 | Cross-site scripting (XSS) vulnerability in components/filemanager/dialog.php in Codiad 2.4.3 allows remote attackers to inject arbitrary web script or HTML via the short_name parameter in a rename action. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see… | |||
| CVE-2014-9581 | 0.03 | — | 0.04 | Jan 8, 2015 | Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more… | |||
| CVE-2013-7257 | 0.00 | — | 0.02 | Jan 3, 2014 | Cross-site scripting (XSS) vulnerability in Codiad 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the Project Name field. |
- risk 0.70cvss 9.8epss 0.38
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
- risk 0.68cvss 9.8epss 0.19
Codiad Web IDE through 2.8.4 allows PHP Code injection.
- risk 0.57cvss 8.8epss 0.02
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only available to admin users and it isn't CSRF protected in…
- risk 0.57cvss 9.8epss 0.08
components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demonstrated by search_file_type.
- risk 0.51cvss 7.2epss 0.18
Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.
- risk 0.49cvss 7.5epss 0.01
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234…
- risk 0.49cvss 7.5epss 0.01
Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.
- risk 0.47cvss 7.2epss 0.03
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin privileges could use the plugin install feature to make the server request any URL via components/market/class.market.php. This…
- risk 0.40cvss 6.1epss 0.01
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later. The vulnerability occurs because of improper sanitization of the folder's name $path variable in components/filemanager/class.filemanager.php. NOTE: the…
- risk 0.35cvss 5.4epss 0.00
Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.
- risk 0.13cvss 3.1epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function saveJSON of the file components/install/process.php. The manipulation of the argument data leads to information disclosure. The…
- CVE-2014-9582Jan 8, 2015risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in components/filemanager/dialog.php in Codiad 2.4.3 allows remote attackers to inject arbitrary web script or HTML via the short_name parameter in a rename action. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see…
- CVE-2014-9581Jan 8, 2015risk 0.03cvss —epss 0.04
Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more…
- CVE-2013-7257Jan 3, 2014risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in Codiad 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the Project Name field.