Savane
Vendor:
First CVE: Apr 8, 2024 · Active for 2 years
4
Total CVEs
More Total CVEs than 72% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Savane over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 8, 2024
2 years ago
Most Recent CVE
Apr 11, 2024
834 days ago
CVE Severity & Scoring
Savane4 CVEs
25%
75%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (25.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (75.0%)
Unknown0 (0.0%)
Required1 (25.0%)
Privileges Required
Low1 (25.0%)
High1 (25.0%)
None2 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27632HIGH An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function. | Apr 8, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-29399HIGH An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component. | Apr 11, 2024 | 7.6 | 21 | NO | NO |
CVE-2024-27630HIGH Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file functi | Apr 8, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-27631MEDIUM Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php | Apr 8, 2024 | 6.0 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Savane
Top CWEs
Versions
No cataloged versions.