Vulnerabilities > Mecodia

DATE CVE VULNERABILITY TITLE RISK
2024-08-02 CVE-2024-41517 Unspecified vulnerability in Mecodia Feripro
An Incorrect Access Control vulnerability in "/admin/benutzer/institution/rechteverwaltung/uebersicht" in Feripro <= v2.2.3 allows remote attackers to get a list of all users and their corresponding privileges.
network
low complexity
mecodia
5.3
2024-08-02 CVE-2024-41518 Unspecified vulnerability in Mecodia Feripro
An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allows remote attackers to export an XLSX file with information about registrations and participants.
network
low complexity
mecodia
7.5
2024-08-02 CVE-2024-41519 Cross-site Scripting vulnerability in Mecodia Feripro
Feripro <= v2.2.3 is vulnerable to Cross Site Scripting (XSS) via "/admin/programm/<program_id>/zuordnung/veranstaltungen/<event_id>" through the "school" input field.
network
low complexity
mecodia CWE-79
5.4