Vulnerabilities > Larvata

DATE CVE VULNERABILITY TITLE RISK
2021-08-09 CVE-2021-37211 Cross-site Scripting vulnerability in Larvata Flygo
The bulletin function of Flygo does not filter special characters while a new announcement is added.
network
larvata CWE-79
3.5
2021-08-09 CVE-2021-37212 Authorization Bypass Through User-Controlled Key vulnerability in Larvata Flygo 1.90.5
The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability.
network
low complexity
larvata CWE-639
5.5
2021-08-09 CVE-2021-37213 Authorization Bypass Through User-Controlled Key vulnerability in Larvata Flygo 1.90.5
The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability.
network
low complexity
larvata CWE-639
4.0
2021-08-09 CVE-2021-37214 Authorization Bypass Through User-Controlled Key vulnerability in Larvata Flygo 1.90.5
The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability.
network
low complexity
larvata CWE-639
6.5
2021-08-09 CVE-2021-37215 Authorization Bypass Through User-Controlled Key vulnerability in Larvata Flygo 1.90.5
The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability.
network
low complexity
larvata CWE-639
4.0