Vulnerabilities > Angry Frog

DATE CVE VULNERABILITY TITLE RISK
2019-07-26 CVE-2019-14228 Cross-Site Request Forgery (CSRF) vulnerability in Angry-Frog Xavier 3.0
Xavier PHP Management Panel 3.0 is vulnerable to Reflected POST-based XSS via the username parameter when registering a new user at admin/includes/adminprocess.php.
4.3
2017-10-28 CVE-2017-15949 SQL Injection vulnerability in Angry-Frog Xavier 2.4
Xavier PHP Management Panel 2.4 allows SQL injection via the usertoedit parameter to admin/adminuseredit.php or the log_id parameter to admin/editgroup.php.
network
low complexity
angry-frog CWE-89
6.5