← Back

Codefever

codefever

Vendor: Pgyer • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pgyer
1Codefever
Nov 21, 2024
Sep 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request to the branchList component.
1Pgyer
1Codefever
Feb 12, 2025
Apr 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
codefever before 2023.2.7-commit-b1c2e7f was discovered to contain a remote code execution (RCE) vulnerability via the component /controllers/api/user.php.