Filtered by vendor Gnu Subscriptions
Filtered by product Savane Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-29399 1 Gnu 1 Savane 2025-06-17 7.6 High
An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component.
CVE-2024-27631 1 Gnu 1 Savane 2024-11-21 6.0 Medium
Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php