Megabip is a focused web application platform with a modest vulnerability footprint concentrated in its core product and characterized by recurrent input-handling and code-execution weakness classes including code injection, cross-site scripting, SQL injection, and unrestricted file upload. These flaws reflect typical risks in web-facing applications where user input flows through multiple processing stages; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Megabip over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1577CRITICAL Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP code t | Jun 12, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-1659CRITICAL Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authentication. This issue affects M | Jun 12, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-1576CRITICAL SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the | Jun 12, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-5378MEDIUM Improper Input Validation vulnerability in MegaBIP and already unsupported SmodBIP software allows for Stored XSS.This issue affects SmodBIP in all versions and MegaBIP in version | Jan 29, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Megabip.
Media articles that mention a CVE ID that affects a product developed by Megabip — matched by CVE ID, not by vendor name.