Vulnerabilities > Traq
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-02-11 | CVE-2018-20780 | Cross-Site Request Forgery (CSRF) vulnerability in Traq 3.7.1 Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1). | 8.8 |
2019-02-11 | CVE-2018-20779 | SQL Injection vulnerability in Traq 3.7.1 Traq 3.7.1 allows SQL Injection via a tickets?search= URI. | 9.8 |