İçeriğe atla
Noroxi

opencats kayıtları

opencats üreticisine ait 24 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

24 kayıt
  • CVE-2021-41560
    42Planlayın

    OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.

    KritikCVSS 9,8Kavram kanıtıEPSS %11

    opencats · opencats15 Ara 2021

  • CVE-2021-25294
    42Planlayın

    OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution.

    KritikCVSS 9,8İstismar yokEPSS %11

    opencats · opencats18 Oca 2021

  • CVE-2023-27293
    41Planlayın

    Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer

    OrtaCVSS 6,1İstismar yokEPSS %57

    opencats · opencats28 Şub 2023

  • CVE-2022-43019
    40Planlayın

    OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.

    KritikCVSS 9,8İstismar yokEPSS %2

    opencats · opencats19 Eki 2022

  • CVE-2022-48011
    39İzleyin

    Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.

    KritikCVSS 9,8İstismar yokEPSS %1

    opencats · opencats27 Oca 2023

  • CVE-2019-13358
    37İzleyin

    lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system.

    YüksekCVSS 7,5Kavram kanıtıEPSS %24

    opencats · opencats5 Tem 2019

  • CVE-2022-43022
    26İzleyin

    OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.

    OrtaCVSS 6,5İstismar yokEPSS %1

    opencats · opencats19 Eki 2022

  • CVE-2022-43020
    26İzleyin

    OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.

    OrtaCVSS 6,5İstismar yokEPSS %1

    opencats · opencats19 Eki 2022

  • CVE-2022-43021
    26İzleyin

    OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.

    OrtaCVSS 6,5İstismar yokEPSS %1

    opencats · opencats19 Eki 2022

  • CVE-2022-43023
    26İzleyin

    OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.

    OrtaCVSS 6,5İstismar yokEPSS %1

    opencats · opencats19 Eki 2022

  • CVE-2021-25295
    24İzleyin

    OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.

    OrtaCVSS 6,1İstismar yokEPSS %2

    opencats · opencats18 Oca 2021

  • CVE-2022-43016
    24İzleyin

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    opencats · opencats19 Eki 2022

  • CVE-2022-43017
    24İzleyin

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    opencats · opencats19 Eki 2022

  • CVE-2022-43018
    24İzleyin

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email fu

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    opencats · opencats19 Eki 2022

  • CVE-2022-43015
    24İzleyin

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    opencats · opencats19 Eki 2022

  • CVE-2022-43014
    24İzleyin

    OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    opencats · opencats19 Eki 2022

  • CVE-2022-48012
    24İzleyin

    Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=setti

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    opencats · opencats27 Oca 2023

  • CVE-2023-27292
    21İzleyin

    An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.

    OrtaCVSS 5,4Kavram kanıtıEPSS %1

    opencats · opencats28 Şub 2023

  • CVE-2023-27294
    21İzleyin

    Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit m

    OrtaCVSS 5,4İstismar yokEPSS %1

    opencats · opencats28 Şub 2023

  • CVE-2022-48013
    21İzleyin

    Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar.

    OrtaCVSS 5,4İstismar yokEPSS %1

    opencats · opencats27 Oca 2023

  • CVE-2023-26847
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted

    OrtaCVSS 5,4İstismar yokEPSS %0

    opencats · opencats11 Nis 2023

  • CVE-2023-26846
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted

    OrtaCVSS 5,4İstismar yokEPSS %0

    opencats · opencats11 Nis 2023

  • CVE-2023-27295
    21İzleyin

    Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests.

    OrtaCVSS 5,4İstismar yokEPSS %0

    opencats · opencats28 Şub 2023

  • CVE-2023-26845
    17İzleyin

    A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via unspecified vectors.

    OrtaCVSS 4,3İstismar yokEPSS %0

    opencats · opencats11 Nis 2023