This issue has been fixed in all versions of CEVAS.

Versions of CEVAS prior to 1.02.28 contain a SQL injection vulnerability.

These issues have been resolved in all versions of CEVAS.

Versions of CEVAS prior to 1.02.24 contain a cross-site scripting vulnerability.

This issue has been resolved in all versions of CEVAS.

Versions of CEVAS prior to 1.02.21 contain a cross-site request forgery vulnerability.

This issue has been resolved in all versions of CEVAS.

Versions of CEVAS prior to 1.02.16 contain a cross-site scripting vulnerability.

This issue has been resolved in all versions of CEVAS.

Versions of CEVAS prior to 1.02.12 contain a cross-site request forgery vulnerability.

This issue has been resolved in all versions of CEVAS.

Versions of CEVAS prior to 1.02.10 contain a SQL injection vulnerability.
In versions of CEVAS prior to 1.02.10, SQL injection could be used to access sensitive information in the database.
This issue has been resolved in all versions of CEVAS.

Versions of CEVAS prior to 1.02.7 contain a SQL injection vulnerability.
This issue has been resolved in all versions of CEVAS.

Versions of

SQL Injection - CEVAS 1.02.7

Versions of CEVAS prior to 1.02.6 contain a SQL injection vulnerability.
This issue has been resolved in all versions of CEVAS.

Versions of CEVAS prior to 1.02.3 contain a cross-site scripting vulnerability.
This issue has been resolved in all versions of CEVAS.

SQL Injection Vulnerabilities

CEVAS contains a SQL injection vulnerability.
The issue has been resolved in all versions of CEVAS.

CEVAS Common Vulnerabilities and Exposures

Versions of CEVAS prior to 1.02.4 contain a SQL injection vulnerability.
This issue has been resolved in all versions of CEVAS.

Versions of CEVAS prior to 1.02.3 contain a cross-site scripting vulnerability.
This issue has been resolved in all versions of CEVAS.

Timeline

Published on: 10/28/2022 02:15:00 UTC
Last modified on: 11/01/2022 15:41:00 UTC

References