Vulnerabilities
Vulnerable Software
Ctparental Project:  >> Ctparental  Security Vulnerabilities
CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_help.php, the 'categories' variable is assigned with the content of the query string param 'cat' without sanitization or encoding, enabling an attacker to inject malicious code into the output webpage.
CVSS Score
6.1
EPSS Score
0.002
Published
2021-08-10
CTparental before 4.45.03 is vulnerable to cross-site request forgery (CSRF) in the CTparental admin panel. By combining CSRF with XSS, an attacker can trick the administrator into clicking a link that cancels the filtering for all standard users.
CVSS Score
8.8
EPSS Score
0.001
Published
2021-08-10
CTparental before 4.45.07 is affected by a code execution vulnerability in the CTparental admin panel. Because The file "bl_categories_help.php" is vulnerable to directory traversal, an attacker can create a file that contains scripts and run arbitrary commands.
CVSS Score
7.8
EPSS Score
0.001
Published
2021-08-10


Contact Us

Shodan ® - All rights reserved