vFairs
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-26678 | Hig | 0.57 | 8.8 | 0.02 | May 26, 2021 | vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execution. | ||
| CVE-2020-26677 | Hig | 0.57 | 8.8 | 0.01 | May 26, 2021 | Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API. | ||
| CVE-2020-26680 | Med | 0.35 | 5.4 | 0.00 | May 26, 2021 | In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this… | ||
| CVE-2020-26679 | Med | 0.28 | 4.3 | 0.01 | May 26, 2021 | vFairs 3.3 is affected by Insecure Permissions. Any user logged in to a vFairs virtual conference or event can modify any other users profile information or profile picture. After receiving any user's unique identification number and their own, an HTTP POST request can be made… |
- risk 0.57cvss 8.8epss 0.02
vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execution.
- risk 0.57cvss 8.8epss 0.01
Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.
- risk 0.35cvss 5.4epss 0.00
In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this…
- risk 0.28cvss 4.3epss 0.01
vFairs 3.3 is affected by Insecure Permissions. Any user logged in to a vFairs virtual conference or event can modify any other users profile information or profile picture. After receiving any user's unique identification number and their own, an HTTP POST request can be made…