Skip to main content

Vendor/product archive

gnu / savane CVEs

Beta · best-effort

4 CVEs tagged to gnu / savane0 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2024-29399

Published Apr 11, 2024

An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component.

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27632

Published Apr 8, 2024

An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27631

Published Apr 8, 2024

Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27630

Published Apr 8, 2024

Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file funct…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1