Vulnerabilities
Vulnerable Software
Bedita:  >> Bedita  >> 3.1.0  Security Vulnerabilities
BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.
CVSS Score
9.8
EPSS Score
0.003
Published
2019-08-26
An issue was discovered in BEdita before 3.7.0. A cross-site scripting (XSS) attack occurs via a crafted pages/showObjects URI, as demonstrated by appending a payload to a pages/showObjects/2/0/0/leafs URI.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-07-05
Multiple cross-site scripting (XSS) vulnerabilities in BEdita before 3.6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cfg[projectName] parameter to index.php/admin/saveConfig, the (2) data[stats_provider_url] parameter to index.php/areas/saveArea, or the (3) data[description] parameter to index.php/areas/saveSection.
CVSS Score
4.3
EPSS Score
0.035
Published
2015-09-04


Contact Us

Shodan ® - All rights reserved