Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Doorgets Subscribe
Filtered by product Doorgets Cms
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-11619 1 Doorgets 1 Doorgets Cms 2019-05-01 4.0 MEDIUM 4.9 MEDIUM
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=analytics. A remote background administrator privilege user (or a user with permission to manage configuration analytics) could exploit the vulnerability to obtain database sensitive information.
CVE-2014-1459 1 Doorgets 1 Doorgets Cms 2018-10-09 6.5 MEDIUM N/A
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the _position_down_id parameter. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.