Vulnerabilities > Pghero Project

DATE CVE VULNERABILITY TITLE RISK
2023-01-05 CVE-2023-22626 Information Exposure Through an Error Message vulnerability in Pghero Project Pghero
PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message.
network
low complexity
pghero-project CWE-209
7.5
2020-08-05 CVE-2020-16253 Cross-Site Request Forgery (CSRF) vulnerability in Pghero Project Pghero
The PgHero gem through 2.6.0 for Ruby allows CSRF.
5.8