Zfaka ProjectCVEs & Vulnerabilities
2 CVEs affecting Zfaka Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
zfaka 2
CVE-2022-24553CRITICAL
An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execution.
21 Feb 2022
9.8
CVSS
CVE-2022-22294CRITICAL
A SQL injection vulnerability exists in ZFAKA<=1.43 which an attacker can use to complete SQL injection in the foreground and add a background administrator account.
28 Jan 2022
9.8
CVSS
← PrevPage 1 / 1Next →