VYPR
Vendor

vFairs

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2020-26678HigMay 26, 2021
    risk 0.57cvss 8.8epss 0.02

    vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execution.

  • CVE-2020-26677HigMay 26, 2021
    risk 0.57cvss 8.8epss 0.01

    Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.

  • CVE-2020-26680MedMay 26, 2021
    risk 0.35cvss 5.4epss 0.00

    In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this…

  • CVE-2020-26679MedMay 26, 2021
    risk 0.28cvss 4.3epss 0.01

    vFairs 3.3 is affected by Insecure Permissions. Any user logged in to a vFairs virtual conference or event can modify any other users profile information or profile picture. After receiving any user's unique identification number and their own, an HTTP POST request can be made…