rodber/chevereto-free

rodber/chevereto-free

Releases33
Frequency2 months 16 hours
Last Release
Stars2.79K
๐Ÿ‘‰ Go to chevereto/chevereto for newer Chevereto releases. Self-hosted image sharing software, your own Flickr/Imgur with your very own rules.

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICALโ€”

Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration installation. Attackers can manipulate the database table prefix parameter to write a PHP shell file and execute arbitrary system commands through a crafted POST request.

โ€”3.5 LOW

Chevereto Free before 1.0.13 has XSS.