egavilanmedia has 5 CVEs on record. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: user_registration_and_login_system_with_admin_panel (3), ecm_address_book (1), user_registration_&_login_system_with_admin_panel (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- user_registration_and_login_system_with_admin_panel 3
- ecm_address_book 1
- user_registration_&_login_system_with_admin_panel 1
Worst active — by depth score
CVE-2020-35276Critical· 9.8EgavilanMedia ECM Address Book 1.0 is affected by SQL injection54CVE-2020-35273High· 8.0EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel44CVE-2020-29228High· 7.5EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.41CVE-2020-29230Medium· 6.1EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user34CVE-2020-29231Medium· 5.4EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page30
egavilanmedia vulnerabilities
CVEs affecting egavilanmedia, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2020-29231Medium· 5.4EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and eac…
CVE-2020-29230Medium· 6.1EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerability can result in the attacker injecting…
CVE-2020-29228High· 7.5EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.
CVE-2020-35276Critical· 9.8EgavilanMedia ECM Address Book 1.0 is affected by SQL injection
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
CVE-2020-35273High· 8.0EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel
EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attacker can update any user's account.