vfairs has 4 CVEs on record. The median CVSS is 7.1 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Worst active — by depth score
CVE-2020-26678High· 8.8vFairs 3.3 is affected by Remote Code Execution49CVE-2020-26677High· 8.8Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.49CVE-2020-26680Medium· 5.4In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload30CVE-2020-26679Medium· 4.3vFairs 3.3 is affected by Insecure Permissions24
vfairs vulnerabilities
CVEs affecting vfairs, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2020-26680Medium· 5.4In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload
In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentio…
CVE-2020-26679Medium· 4.3vFairs 3.3 is affected by Insecure Permissions
vFairs 3.3 is affected by Insecure Permissions. Any user logged in to a vFairs virtual conference or event can modify any other users profile information or profile picture. After receiving any user's unique identification number and the…
CVE-2020-26678High· 8.8vFairs 3.3 is affected by Remote Code Execution
vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execut…
CVE-2020-26677High· 8.8Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.
Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.