Vulnerabilities > Monitorr > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-04-12 CVE-2020-28872 Incorrect Authorization vulnerability in Monitorr 1.7.6M
An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to create valid credentials.
network
low complexity
monitorr CWE-863
critical
9.8
2021-02-10 CVE-2020-28871 Unrestricted Upload of File with Dangerous Type vulnerability in Monitorr 1.7.6M
Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.
network
low complexity
monitorr CWE-434
critical
9.8