Vulnerabilities
11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-26557 | Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter. Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2017-20178 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function saveJSON of the file components/install/process.php. The manipulation of the argument data leads to information disclosure. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 2.8.1 is able to address this issue. The patch is identified as 517119de673e62547ee472a730be0604f44342b5. It is recommended to upgrade the affected component. VDB-221498 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2020-23355 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234 something can successfully authenticate. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2020-14042 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later. ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later. The vulnerability occurs because of improper sanitization of the folder's name $path variable in components/filemanager/class.filemanager.php. NOTE: the vendor states "Codiad is no longer under active maintenance by core contributors." NVD description · AI analysis pending | 6.1 | 1% | PoC ×2 |
| — | |
| CVE-2020-14043 +1 in the same advisory: …14044 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only available to admin users and it isn't CSRF protected in components/market/controller.php. This might cause admins to make a vulnerable request without them knowing and result in remote code execution. NOTE: the vendor states "Codiad is no longer under active maintenance by core contributors." NVD description · AI analysis pending | 8.8 group max | 2% | PoC |
| — | |
| CVE-2019-19208 | Codiad Web IDE through 2.8.4 allows PHP Code injection. Codiad Web IDE through 2.8.4 allows PHP Code injection. NVD description · AI analysis pending | 9.8 | 19% | PoC ×4 |
| — | |
| CVE-2018-19423 | Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file. Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file. NVD description · AI analysis pending | 7.2 | 18% | PoC ×2 |
| — | |
| CVE-2018-14009 | Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689. Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689. NVD description · AI analysis pending | 9.8 | 38% | PoC ×2 |
| — | |
| CVE-2017-1000125 | Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell. Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2017-11366 | components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded in paramete components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demonstrated by search_file_type. NVD description · AI analysis pending | 9.8 | 8% | PoC |
| — |