Vulnerabilities > Pearadmin

DATE CVE VULNERABILITY TITLE RISK
2023-08-11 CVE-2021-29378 SQL Injection vulnerability in Pearadmin Pear Admin Think 2.1.2
SQL Injection in pear-admin-think version 2.1.2, allows attackers to execute arbitrary code and escalate privileges via crafted GET request to Crud.php.
network
low complexity
pearadmin CWE-89
8.8
2023-04-25 CVE-2023-30417 Cross-site Scripting vulnerability in Pearadmin Pear Admin Boot
A cross-site scripting (XSS) vulnerability in Pear-Admin-Boot up to v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title of a private message.
network
low complexity
pearadmin CWE-79
5.4
2022-03-29 CVE-2022-23903 Cross-site Scripting vulnerability in Pearadmin Pear Admin Think
A Cross Site Scripting (XSS) vulnerability exists in pearadmin pear-admin-think <=5.0.6, which allows a login account to access arbitrary functions and cause stored XSS through a fake User-Agent.
network
pearadmin CWE-79
3.5
2021-08-12 CVE-2021-29377 Unrestricted Upload of File with Dangerous Type vulnerability in Pearadmin Think
Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely.
network
low complexity
pearadmin CWE-434
7.5