Known Vulnerabilities for Indexhibit by Indexhibit
Listed below are 8 of the newest known vulnerabilities associated with "Indexhibit" by "Indexhibit".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-18127 json | An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files. | 6.5 - MEDIUM | 2021-08-30 | 2022-10-05 |
| CVE-2020-18126 json | Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers to exe... | 5.4 - MEDIUM | 2021-08-30 | 2021-09-02 |
| CVE-2020-18125 json | A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attackers t... | 6.1 - MEDIUM | 2021-08-30 | 2021-09-02 |
| CVE-2020-18124 json | A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords... | 5.7 - MEDIUM | 2021-08-30 | 2021-09-02 |
| CVE-2020-18123 json | A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accounts. | 6.5 - MEDIUM | 2021-08-30 | 2021-09-02 |
| CVE-2020-18121 json | A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell. | 8.8 - HIGH | 2021-08-30 | 2021-09-02 |
| CVE-2019-16314 json | Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2. | 9.8 - CRITICAL | 2019-09-14 | 2021-07-21 |
| CVE-2019-8954 json | In Indexhibit 2.1.5, remote attackers can execute arbitrary code via the v parameter (in conjunction with the id parameter) i... | 8.8 - HIGH | 2019-02-20 | 2019-02-21 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Indexhibit | Indexhibit | 2.1.5 |