Vulnerabilities > Traq

DATE CVE VULNERABILITY TITLE RISK
2019-02-11 CVE-2018-20780 Cross-Site Request Forgery (CSRF) vulnerability in Traq 3.7.1
Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1).
network
traq CWE-352
6.8
2019-02-11 CVE-2018-20779 SQL Injection vulnerability in Traq 3.7.1
Traq 3.7.1 allows SQL Injection via a tickets?search= URI.
network
low complexity
traq CWE-89
7.5