📦 Allegra

by Alltena

🔍 What is Allegra?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-6216

CRITICAL CVSS 9.8 Jun 21, 2025

This vulnerability allows remote attackers to bypass authentication in Allegra by exploiting a predictable password reset token generation mechanism. Attackers can reset passwords and gain unauthorize...

CVE-2023-51638

CRITICAL CVSS 9.8 Nov 22, 2024

This vulnerability allows remote attackers to bypass authentication on Allegra installations by exploiting hard-coded database credentials. Attackers can gain unauthorized access without authenticatio...

CVE-2024-5580

HIGH CVSS 7.2 Nov 22, 2024

This vulnerability allows authenticated remote attackers to execute arbitrary code on affected Allegra installations by exploiting a deserialization flaw in the loadFieldMatch method. Attackers can ac...

CVE-2023-52332

HIGH CVSS 7.5 Nov 22, 2024

This directory traversal vulnerability in Allegra's serveMathJaxLibraries method allows unauthenticated remote attackers to read arbitrary files on the server. Affected installations of Allegra softwa...

CVE-2023-51644

HIGH CVSS 7.3 Nov 22, 2024

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on Allegra installations due to improper access control in Struts configuration. Affected systems are Allegra insta...

CVE-2023-51646

MEDIUM CVSS 4.7 Nov 22, 2024

This vulnerability allows authenticated remote attackers to bypass authentication and execute arbitrary code on Allegra installations via directory traversal in the uploadSimpleFile method. Attackers ...

CVE-2023-51648

MEDIUM CVSS 6.5 Nov 22, 2024

This vulnerability allows authenticated remote attackers to read arbitrary files on Allegra installations via directory traversal in the getFileContentAsString method. Attackers can exploit this to di...

CVE-2023-52334

MEDIUM CVSS 6.5 Nov 22, 2024

This directory traversal vulnerability in Allegra's downloadAttachmentGlobal function allows authenticated attackers to read arbitrary files on the server. Attackers can exploit this to steal sensitiv...

CVE-2023-51640

MEDIUM CVSS 4.7 Nov 22, 2024

This vulnerability allows authenticated remote attackers to bypass authentication and execute arbitrary code via a directory traversal flaw in Allegra's extractZippedFile method. It affects Allegra in...

CVE-2023-51642

MEDIUM CVSS 6.3 Nov 22, 2024

This vulnerability allows remote authenticated attackers to execute arbitrary code on affected Allegra installations by exploiting a deserialization flaw in the loadFieldMatch method. Attackers can cr...