Vulnerabilities
5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-33559 +1 in the same advisory: …33558 | A local file inclusion vulnerability via the lang parameter in OcoMon before v4.0.1 allows attackers to execute arbitrary code by supplying a crafted PHP file. A local file inclusion vulnerability via the lang parameter in OcoMon before v4.0.1 allows attackers to execute arbitrary code by supplying a crafted PHP file. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2022-40798 | OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct email its possible to account takeover. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2022-41391 +1 in the same advisory: …41390 | OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php. OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — |