Metrics
Affected Vendors & Products
Mon, 09 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Demo
Demo alive Parish |
|
| Vendors & Products |
Demo
Demo alive Parish |
Fri, 06 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Alive Parish 2.0.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the key parameter in the search endpoint. Attackers can also upload arbitrary files via the person photo upload functionality to the images/uploaded directory for remote code execution. | |
| Title | Alive Parish 2.0.4 SQL Injection and Arbitrary File Upload | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-09T15:24:57.224Z
Reserved: 2026-03-06T11:33:03.992Z
Link: CVE-2018-25176
Updated: 2026-03-09T15:24:51.345Z
Status : Awaiting Analysis
Published: 2026-03-06T13:15:59.440
Modified: 2026-03-09T13:35:34.633
Link: CVE-2018-25176
No data.