İçeriğe atla
Noroxi

rangerstudio kayıtları

rangerstudio üreticisine ait 17 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%17,6
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

17 kayıt
  • CVE-2019-13983
    39İzleyin

    Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php

    KritikCVSS 9,8İstismar yokEPSS %1

    rangerstudio · directus 7 api19 Tem 2019

  • CVE-2018-10723
    39İzleyin

    Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.

    KritikCVSS 9,8İstismar yokEPSS %1

    rangerstudio · directus5 May 2018

  • CVE-2021-29641
    36İzleyin

    Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include the ability to u

    YüksekCVSS 8,8İstismar yokEPSS %5

    rangerstudio · directus7 Nis 2021

  • CVE-2019-13979
    36İzleyin

    In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution.

    YüksekCVSS 8,8İstismar yokEPSS %3

    rangerstudio · directus 7 api19 Tem 2019

  • CVE-2019-13980
    36İzleyin

    In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals

    YüksekCVSS 8,8İstismar yokEPSS %2

    rangerstudio · directus 7 api19 Tem 2019

  • CVE-2019-13984
    35İzleyin

    Directus 7 API before 2.3.0 does not validate uploaded files.

    YüksekCVSS 8,8İstismar yokEPSS %2

    rangerstudio · directus 7 api19 Tem 2019

  • CVE-2021-26594
    35İzleyin

    In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end.

    YüksekCVSS 8,8İstismar yokEPSS %1

    rangerstudio · directus23 Şub 2021

  • CVE-2021-26593
    30İzleyin

    In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}.

    YüksekCVSS 7,5İstismar yokEPSS %1

    rangerstudio · directus23 Şub 2021

  • CVE-2022-24814
    24İzleyin

    Cross-site Scripting in Directus

    OrtaCVSS 6,1İstismar yokEPSS %1

    rangerstudio · directus4 Nis 2022

  • CVE-2019-13981
    21İzleyin

    In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ di

    OrtaCVSS 5,3İstismar yokEPSS %2

    rangerstudio · directus 7 api19 Tem 2019

  • CVE-2019-13982
    21İzleyin

    interfaces/markdown/input.vue in Directus 7 Application before 7.7.0 does not sanitize Markdown text before rendering a preview.

    OrtaCVSS 5,3İstismar yokEPSS %1

    rangerstudio · directus 719 Tem 2019

  • CVE-2021-27583
    21İzleyin

    In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature.

    OrtaCVSS 5,3İstismar yokEPSS %1

    rangerstudio · directus23 Şub 2021

  • CVE-2021-26595
    21İzleyin

    In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site,

    OrtaCVSS 5,3İstismar yokEPSS %1

    rangerstudio · directus23 Şub 2021

  • CVE-2022-22116
    21İzleyin

    Directus - Stored Cross-Site Scripting (XSS) via SVG File Upload

    OrtaCVSS 5,4İstismar yokEPSS %1

    rangerstudio · directus10 Oca 2022

  • CVE-2022-22117
    21İzleyin

    Directus - Stored Cross-Site Scripting (XSS) in Profile Avatar Image

    OrtaCVSS 5,4İstismar yokEPSS %1

    rangerstudio · directus10 Oca 2022

  • CVE-2023-27474
    21İzleyin

    HTML Injection in Password Reset email to custom Reset URL in directus

    OrtaCVSS 5,4İstismar yokEPSS %1

    rangerstudio · directus6 Mar 2023

  • CVE-2022-23080
    20İzleyin

    directus - SSRF which leads to internal port scan

    OrtaCVSS 5,0İstismar yokEPSS %1

    rangerstudio · directus22 Haz 2022