VYPR
Vendor

Mocodo

Products
2
CVEs
2
Across products
3
Status
Private

Products

2

Recent CVEs

2
  • CVE-2024-35373CriMay 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.

  • CVE-2024-35374CriMay 24, 2024
    risk 0.57cvss 9.8epss 0.03

    Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.