CVE-2019-14987
Published Aug 13, 2019Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions.
Vendor archive
3 CVEs tagged to vendor schben — 0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.
Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions.
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by…
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.