CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665. |
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668. |
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680. |
A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code. |