ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-16531
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.

LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.

NVD description · AI analysis pending
8.83% PoC
  • layerbb layerbb
CVE-2019-13973
+2 in the same advisory: …13974 …13972
LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used.

LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • layerbb layerbb
CVE-2018-17996
+1 in the same advisory: …17997
LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/dele

LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/.

NVD description · AI analysis pending
6.5
group max
3% PoC ×3
  • layerbb layerbb
CVE-2018-17988
LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter.

LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter.

NVD description · AI analysis pending
9.82% PoC ×2
  • layerbb layerbb