Перейти к содержимому
Noroxi

Записи opencats

24 опубликованных записей вендора opencats.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

24 записей
  • CVE-2021-41560
    42В плане

    OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.

    КритическаяCVSS 9,8Proof of conceptEPSS 11 %

    opencats · opencats15 дек. 2021 г.

  • CVE-2021-25294
    42В плане

    OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution.

    КритическаяCVSS 9,8Эксплойта нетEPSS 11 %

    opencats · opencats18 янв. 2021 г.

  • CVE-2023-27293
    41В плане

    Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer

    СредняяCVSS 6,1Эксплойта нетEPSS 57 %

    opencats · opencats28 февр. 2023 г.

  • CVE-2022-43019
    40В плане

    OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    opencats · opencats19 окт. 2022 г.

  • CVE-2022-48011
    39Наблюдать

    Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    opencats · opencats27 янв. 2023 г.

  • CVE-2019-13358
    37Наблюдать

    lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system.

    ВысокаяCVSS 7,5Proof of conceptEPSS 24 %

    opencats · opencats5 июл. 2019 г.

  • CVE-2022-43022
    26Наблюдать

    OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    opencats · opencats19 окт. 2022 г.

  • CVE-2022-43020
    26Наблюдать

    OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    opencats · opencats19 окт. 2022 г.

  • CVE-2022-43021
    26Наблюдать

    OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    opencats · opencats19 окт. 2022 г.

  • CVE-2022-43023
    26Наблюдать

    OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    opencats · opencats19 окт. 2022 г.

  • CVE-2021-25295
    24Наблюдать

    OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    opencats · opencats18 янв. 2021 г.

  • CVE-2022-43016
    24Наблюдать

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    opencats · opencats19 окт. 2022 г.

  • CVE-2022-43017
    24Наблюдать

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    opencats · opencats19 окт. 2022 г.

  • CVE-2022-43018
    24Наблюдать

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email fu

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    opencats · opencats19 окт. 2022 г.

  • CVE-2022-43015
    24Наблюдать

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    opencats · opencats19 окт. 2022 г.

  • CVE-2022-43014
    24Наблюдать

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    opencats · opencats19 окт. 2022 г.

  • CVE-2022-48012
    24Наблюдать

    Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=setti

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    opencats · opencats27 янв. 2023 г.

  • CVE-2023-27292
    21Наблюдать

    An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.

    СредняяCVSS 5,4Proof of conceptEPSS 1 %

    opencats · opencats28 февр. 2023 г.

  • CVE-2023-27294
    21Наблюдать

    Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit m

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    opencats · opencats28 февр. 2023 г.

  • CVE-2022-48013
    21Наблюдать

    Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    opencats · opencats27 янв. 2023 г.

  • CVE-2023-26847
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    opencats · opencats11 апр. 2023 г.

  • CVE-2023-26846
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    opencats · opencats11 апр. 2023 г.

  • CVE-2023-27295
    21Наблюдать

    Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests.

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    opencats · opencats28 февр. 2023 г.

  • CVE-2023-26845
    17Наблюдать

    A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via unspecified vectors.

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    opencats · opencats11 апр. 2023 г.