arrowjs records
1 published records for vendor arrowjs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
1 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2024-42914No exploit | A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0.arrowjs · arrowcms · CWE-74 | Critical9.1 | — | 0.6% | Aug 23, 2024 |
- CVE-2024-4291436Monitor
A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0.
CriticalCVSS 9.1No exploitEPSS 1%arrowjs · arrowcmsAug 23, 2024