Записи opencats
24 опубликованных записей вендора opencats.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-502 Deserialization of Untrusted Data2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
24 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2021-41560Proof of concept | OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.opencats · opencats · CWE-434 | Критическая9,8 | — | 11,1 % | 15 дек. 2021 г. |
42В плане | CVE-2021-25294Эксплойта нет | OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution.opencats · opencats · CWE-502 | Критическая9,8 | — | 10,9 % | 18 янв. 2021 г. |
41В плане | CVE-2023-27293Эксплойта нет | Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer opencats · opencats · CWE-79 | Средняя6,1 | — | 57,0 % | 28 февр. 2023 г. |
40В плане | CVE-2022-43019Эксплойта нет | OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.opencats · opencats · CWE-502 | Критическая9,8 | — | 2,1 % | 19 окт. 2022 г. |
39Наблюдать | CVE-2022-48011Эксплойта нет | Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.opencats · opencats · CWE-89 | Критическая9,8 | — | 1,1 % | 27 янв. 2023 г. |
37Наблюдать | CVE-2019-13358Proof of concept | lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system.opencats · opencats · CWE-611 | Высокая7,5 | — | 24,3 % | 5 июл. 2019 г. |
26Наблюдать | CVE-2022-43022Эксплойта нет | OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.opencats · opencats · CWE-89 | Средняя6,5 | — | 0,9 % | 19 окт. 2022 г. |
26Наблюдать | CVE-2022-43020Эксплойта нет | OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.opencats · opencats · CWE-89 | Средняя6,5 | — | 0,9 % | 19 окт. 2022 г. |
26Наблюдать | CVE-2022-43021Эксплойта нет | OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.opencats · opencats · CWE-89 | Средняя6,5 | — | 0,9 % | 19 окт. 2022 г. |
26Наблюдать | CVE-2022-43023Эксплойта нет | OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.opencats · opencats · CWE-89 | Средняя6,5 | — | 0,9 % | 19 окт. 2022 г. |
24Наблюдать | CVE-2021-25295Эксплойта нет | OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.opencats · opencats · CWE-79 | Средняя6,1 | — | 1,5 % | 18 янв. 2021 г. |
24Наблюдать | CVE-2022-43016Proof of concept | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.opencats · opencats · CWE-79 | Средняя6,1 | — | 1,5 % | 19 окт. 2022 г. |
24Наблюдать | CVE-2022-43017Proof of concept | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.opencats · opencats · CWE-79 | Средняя6,1 | — | 1,5 % | 19 окт. 2022 г. |
24Наблюдать | CVE-2022-43018Proof of concept | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email fuopencats · opencats · CWE-79 | Средняя6,1 | — | 1,5 % | 19 окт. 2022 г. |
24Наблюдать | CVE-2022-43015Proof of concept | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.opencats · opencats · CWE-79 | Средняя6,1 | — | 1,4 % | 19 окт. 2022 г. |
24Наблюдать | CVE-2022-43014Proof of concept | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.opencats · opencats · CWE-79 | Средняя6,1 | — | 1,4 % | 19 окт. 2022 г. |
24Наблюдать | CVE-2022-48012Proof of concept | Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=settiopencats · opencats · CWE-79 | Средняя6,1 | — | 1,4 % | 27 янв. 2023 г. |
21Наблюдать | CVE-2023-27292Proof of concept | An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.opencats · opencats · CWE-601 | Средняя5,4 | — | 1,0 % | 28 февр. 2023 г. |
21Наблюдать | CVE-2023-27294Эксплойта нет | Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit mopencats · opencats · CWE-79 | Средняя5,4 | — | 0,5 % | 28 февр. 2023 г. |
21Наблюдать | CVE-2022-48013Эксплойта нет | Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar.opencats · opencats · CWE-79 | Средняя5,4 | — | 0,5 % | 27 янв. 2023 г. |
21Наблюдать | CVE-2023-26847Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a craftedopencats · opencats · CWE-79 | Средняя5,4 | — | 0,4 % | 11 апр. 2023 г. |
21Наблюдать | CVE-2023-26846Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a craftedopencats · opencats · CWE-79 | Средняя5,4 | — | 0,4 % | 11 апр. 2023 г. |
21Наблюдать | CVE-2023-27295Эксплойта нет | Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests.opencats · opencats · CWE-352 | Средняя5,4 | — | 0,4 % | 28 февр. 2023 г. |
17Наблюдать | CVE-2023-26845Эксплойта нет | A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via unspecified vectors.opencats · opencats · CWE-352 | Средняя4,3 | — | 0,2 % | 11 апр. 2023 г. |
- CVE-2021-4156042В плане
OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.
КритическаяCVSS 9,8Proof of conceptEPSS 11 %opencats · opencats15 дек. 2021 г.
- CVE-2021-2529442В плане
OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %opencats · opencats18 янв. 2021 г.
- CVE-2023-2729341В плане
Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer
СредняяCVSS 6,1Эксплойта нетEPSS 57 %opencats · opencats28 февр. 2023 г.
- CVE-2022-4301940В плане
OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %opencats · opencats19 окт. 2022 г.
- CVE-2022-4801139Наблюдать
Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %opencats · opencats27 янв. 2023 г.
- CVE-2019-1335837Наблюдать
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system.
ВысокаяCVSS 7,5Proof of conceptEPSS 24 %opencats · opencats5 июл. 2019 г.
- CVE-2022-4302226Наблюдать
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %opencats · opencats19 окт. 2022 г.
- CVE-2022-4302026Наблюдать
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %opencats · opencats19 окт. 2022 г.
- CVE-2022-4302126Наблюдать
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %opencats · opencats19 окт. 2022 г.
- CVE-2022-4302326Наблюдать
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %opencats · opencats19 окт. 2022 г.
- CVE-2021-2529524Наблюдать
OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.
СредняяCVSS 6,1Эксплойта нетEPSS 2 %opencats · opencats18 янв. 2021 г.
- CVE-2022-4301624Наблюдать
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.
СредняяCVSS 6,1Proof of conceptEPSS 1 %opencats · opencats19 окт. 2022 г.
- CVE-2022-4301724Наблюдать
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.
СредняяCVSS 6,1Proof of conceptEPSS 1 %opencats · opencats19 окт. 2022 г.
- CVE-2022-4301824Наблюдать
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email fu
СредняяCVSS 6,1Proof of conceptEPSS 1 %opencats · opencats19 окт. 2022 г.
- CVE-2022-4301524Наблюдать
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.
СредняяCVSS 6,1Proof of conceptEPSS 1 %opencats · opencats19 окт. 2022 г.
- CVE-2022-4301424Наблюдать
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.
СредняяCVSS 6,1Proof of conceptEPSS 1 %opencats · opencats19 окт. 2022 г.
- CVE-2022-4801224Наблюдать
Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=setti
СредняяCVSS 6,1Proof of conceptEPSS 1 %opencats · opencats27 янв. 2023 г.
- CVE-2023-2729221Наблюдать
An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.
СредняяCVSS 5,4Proof of conceptEPSS 1 %opencats · opencats28 февр. 2023 г.
- CVE-2023-2729421Наблюдать
Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit m
СредняяCVSS 5,4Эксплойта нетEPSS 1 %opencats · opencats28 февр. 2023 г.
- CVE-2022-4801321Наблюдать
Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %opencats · opencats27 янв. 2023 г.
- CVE-2023-2684721Наблюдать
A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted
СредняяCVSS 5,4Эксплойта нетEPSS 0 %opencats · opencats11 апр. 2023 г.
- CVE-2023-2684621Наблюдать
A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted
СредняяCVSS 5,4Эксплойта нетEPSS 0 %opencats · opencats11 апр. 2023 г.
- CVE-2023-2729521Наблюдать
Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %opencats · opencats28 февр. 2023 г.
- CVE-2023-2684517Наблюдать
A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via unspecified vectors.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %opencats · opencats11 апр. 2023 г.