Vulnerabilities > Schben

DATE CVE VULNERABILITY TITLE RISK
2019-08-13 CVE-2019-14987 Cross-site Scripting vulnerability in Schben Framework 2.0.7
Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions.
network
schben CWE-79
3.5
2019-08-06 CVE-2019-14347 Forced Browsing vulnerability in Schben Adive
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script.
network
low complexity
schben CWE-425
8.8
2019-08-06 CVE-2019-14346 Cross-Site Request Forgery (CSRF) vulnerability in Schben Adive 2.0.7
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
network
schben CWE-352
4.3