
CVE-2024-38295
https://notcve.org/view.php?id=CVE-2024-38295
13 Jun 2024 — ALCASAR before 3.6.1 allows still_connected.php remote code execution. ALCASAR anterior a 3.6.1 permite la ejecución remota de código still_connected.php. • https://adullact.net/frs/download.php/file/8930/CHANGELOG.md •

CVE-2024-38294
https://notcve.org/view.php?id=CVE-2024-38294
13 Jun 2024 — ALCASAR before 3.6.1 allows email_registration_back.php remote code execution. ALCASAR anterior a 3.6.1 permite la ejecución remota de código email_registration_back.php. • https://adullact.net/frs/download.php/file/8930/CHANGELOG.md •

CVE-2024-38293
https://notcve.org/view.php?id=CVE-2024-38293
13 Jun 2024 — ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php. ALCASAR anterior a 3.6.1 permite CSRF y la ejecución remota de código en Activity.php. • https://adullact.net/frs/download.php/file/8930/CHANGELOG.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE-352: Cross-Site Request Forgery (CSRF) •