Known Vulnerabilities for Rental Bike Script by Rental Bike Script Project
Listed below are 3 of the newest known vulnerabilities associated with "Rental Bike Script" by "Rental Bike Script Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-7434 json | PHP Scripts Mall Rental Bike Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory. | 6.5 - MEDIUM | 2019-03-21 | 2021-07-21 |
| CVE-2019-7433 json | PHP Scripts Mall Rental Bike Script 2.0.3 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature. | 8.8 - HIGH | 2019-03-21 | 2019-03-22 |
| CVE-2019-7432 json | PHP Scripts Mall Rental Bike Script 2.0.3 has HTML injection via the STREET field in the Profile Edit section. | 5.4 - MEDIUM | 2019-03-21 | 2020-08-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rental Bike Script Project | Rental Bike Script | 2.0.3 |