Masterlab is a narrowly scoped vendor represented by a single product line that nevertheless carries outsized severity risk, with its vulnerabilities skewing strongly toward critical-severity outcomes. The recurring exposure centers on application-layer input handling and file-upload validation, including SQL injection, unrestricted file uploads, and server-side request forgery, which are characteristic of web application design gaps that can grant direct database or infrastructure access. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Masterlab over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-7145CRITICAL A vulnerability classified as critical was found in gopeak MasterLab up to 3.3.10. This vulnerability affects the function sqlInject of the file app/ctrl/Framework.php of the compo | Dec 29, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-7146CRITICAL A vulnerability, which was classified as critical, has been found in gopeak MasterLab up to 3.3.10. This issue affects the function sqlInjectDelete of the file app/ctrl/framework/F | Dec 29, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-7144CRITICAL A vulnerability classified as critical has been found in gopeak MasterLab up to 3.3.10. This affects the function sqlInject of the file app/ctrl/framework/Feature.php of the compon | Dec 29, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-7159CRITICAL A vulnerability was found in gopeak MasterLab up to 3.3.10. It has been declared as critical. Affected by this vulnerability is the function add/update of the file app/ctrl/admin/U | Dec 29, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-7147CRITICAL A vulnerability, which was classified as critical, was found in gopeak MasterLab up to 3.3.10. Affected is the function base64ImageContent of the file app/ctrl/User.php. The manipu | Dec 29, 2023 | 9.8 | 25 | NO | NO |
CVE-2020-23534CRITICAL A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter. | Feb 25, 2021 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Masterlab.
Media articles that mention a CVE ID that affects a product developed by Masterlab — matched by CVE ID, not by vendor name.