Known Vulnerabilities for products from Travianz Project
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Travianz Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-36995 json | TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, or th... | 6.1 - MEDIUM | 2023-07-06 | 2023-07-12 |
| CVE-2023-36994 json | In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server c... | 9.8 - CRITICAL | 2023-07-07 | 2023-07-13 |
| CVE-2023-36993 json | The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function ... | 9.8 - CRITICAL | 2023-07-07 | 2023-07-13 |
| CVE-2023-36992 json | PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code. | 7.2 - HIGH | 2023-07-07 | 2023-07-13 |