autolabproject kayıtları
autolabproject üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %54,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-863 Incorrect Authorization1
- CWE-359 Exposure of Private Personal Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2022-41955İstismar yok | Autolab is vulnerable to remote code execution (RCE) via MOSS functionalityautolabproject · autolab · CWE-78 | Yüksek8,8 | — | %1,5 | 13 Oca 2023 |
28İzleyin | CVE-2023-32676İstismar yok | Autolab tar slip in Install Assessment functionality (`GHSL-2023-081`)autolabproject · autolab · CWE-22 | Yüksek7,2 | — | %0,9 | 26 May 2023 |
28İzleyin | CVE-2023-32317İstismar yok | Autolab tar slip in cheat checker functionality (`GHSL-2023-082`)autolabproject · autolab · CWE-22 | Yüksek7,2 | — | %0,9 | 26 May 2023 |
28İzleyin | CVE-2024-53258İstismar yok | download_all_submissions allows student to download another student's submissions in Autolabautolabproject · autolab · CWE-359 | Yüksek7,1 | — | %0,5 | 25 Kas 2024 |
28İzleyin | CVE-2024-49376İstismar yok | Autolab Has Misconfigured Reset Password Permissionsautolabproject · autolab · CWE-287 | Yüksek7,1 | — | %0,5 | 25 Eki 2024 |
27İzleyin | CVE-2022-41956İstismar yok | Autolab is vulnerable to file disclosure via remote handin featureautolabproject · autolab · CWE-22 | Orta6,5 | — | %1,8 | 13 Oca 2023 |
27İzleyin | CVE-2024-53260İstismar yok | Course Roster vulnerable to CSV Injection in Autolabautolabproject · autolab · CWE-1236 | Orta6,8 | — | %0,5 | 27 Kas 2024 |
26İzleyin | CVE-2023-44395İstismar yok | Autolab has Path Traversal vulnerability in Assessment functionalityautolabproject · autolab · CWE-22 | Orta6,5 | — | %0,6 | 22 Oca 2024 |
21İzleyin | CVE-2022-0936İstismar yok | Cross-site Scripting (XSS) - Stored in autolab/autolabautolabproject · autolab · CWE-79 | Orta5,4 | — | %0,7 | 11 Nis 2022 |
19İzleyin | CVE-2024-52584İstismar yok | Autolab has vulnerable submission endpointsautolabproject · autolab · CWE-863 | Orta4,9 | — | %0,3 | 18 Kas 2024 |
4İzleyin | CVE-2024-52585İstismar yok | Autolab has HTML Injection Vulnerabilityautolabproject · autolab · CWE-79 | Düşük1,2 | — | %0,3 | 18 Kas 2024 |
- CVE-2022-4195535İzleyin
Autolab is vulnerable to remote code execution (RCE) via MOSS functionality
YüksekCVSS 8,8İstismar yokEPSS %1autolabproject · autolab13 Oca 2023
- CVE-2023-3267628İzleyin
Autolab tar slip in Install Assessment functionality (`GHSL-2023-081`)
YüksekCVSS 7,2İstismar yokEPSS %1autolabproject · autolab26 May 2023
- CVE-2023-3231728İzleyin
Autolab tar slip in cheat checker functionality (`GHSL-2023-082`)
YüksekCVSS 7,2İstismar yokEPSS %1autolabproject · autolab26 May 2023
- CVE-2024-5325828İzleyin
download_all_submissions allows student to download another student's submissions in Autolab
YüksekCVSS 7,1İstismar yokEPSS %0autolabproject · autolab25 Kas 2024
- CVE-2024-4937628İzleyin
Autolab Has Misconfigured Reset Password Permissions
YüksekCVSS 7,1İstismar yokEPSS %0autolabproject · autolab25 Eki 2024
- CVE-2022-4195627İzleyin
Autolab is vulnerable to file disclosure via remote handin feature
OrtaCVSS 6,5İstismar yokEPSS %2autolabproject · autolab13 Oca 2023
- CVE-2024-5326027İzleyin
Course Roster vulnerable to CSV Injection in Autolab
OrtaCVSS 6,8İstismar yokEPSS %0autolabproject · autolab27 Kas 2024
- CVE-2023-4439526İzleyin
Autolab has Path Traversal vulnerability in Assessment functionality
OrtaCVSS 6,5İstismar yokEPSS %1autolabproject · autolab22 Oca 2024
- CVE-2022-093621İzleyin
Cross-site Scripting (XSS) - Stored in autolab/autolab
OrtaCVSS 5,4İstismar yokEPSS %1autolabproject · autolab11 Nis 2022
- CVE-2024-5258419İzleyin
Autolab has vulnerable submission endpoints
OrtaCVSS 4,9İstismar yokEPSS %0autolabproject · autolab18 Kas 2024
- CVE-2024-525854İzleyin
Autolab has HTML Injection Vulnerability
DüşükCVSS 1,2İstismar yokEPSS %0autolabproject · autolab18 Kas 2024