Known Vulnerabilities for products from Ladybirdweb
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Ladybirdweb".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-25350 json | Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on ... | 8.8 - HIGH | 2023-03-24 | 2023-03-29 |
| CVE-2023-24625 json | Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Refer... | 6.5 - MEDIUM | 2023-03-24 | 2023-11-07 |
| CVE-2023-1724 json | Faveo Helpdesk Enterprise version 6.0.1 allows an attacker with agent permissions to perform privilege escalation on the appl... | 5.4 - MEDIUM | 2023-06-24 | 2023-06-30 |
| CVE-2017-7571 json | public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges. | Not Provided | 2017-04-06 | 2025-04-20 |