rangerstudio kayıtları
rangerstudio üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %17,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-269 Improper Privilege Management1
- CWE-306 Missing Authentication for Critical Function1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-425 Direct Request ('Forced Browsing')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2019-13983İstismar yok | Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.phprangerstudio · directus 7 api · CWE-306 | Kritik9,8 | — | %1,5 | 19 Tem 2019 |
39İzleyin | CVE-2018-10723İstismar yok | Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.rangerstudio · directus · CWE-798 | Kritik9,8 | — | %1,3 | 5 May 2018 |
36İzleyin | CVE-2021-29641İstismar yok | Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include the ability to urangerstudio · directus · CWE-434 | Yüksek8,8 | — | %4,9 | 7 Nis 2021 |
36İzleyin | CVE-2019-13979İstismar yok | In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution.rangerstudio · directus 7 api · CWE-434 | Yüksek8,8 | — | %2,6 | 19 Tem 2019 |
36İzleyin | CVE-2019-13980İstismar yok | In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals rangerstudio · directus 7 api · CWE-434 | Yüksek8,8 | — | %2,5 | 19 Tem 2019 |
35İzleyin | CVE-2019-13984İstismar yok | Directus 7 API before 2.3.0 does not validate uploaded files.rangerstudio · directus 7 api · CWE-434 | Yüksek8,8 | — | %1,6 | 19 Tem 2019 |
35İzleyin | CVE-2021-26594İstismar yok | In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end.rangerstudio · directus · CWE-269 | Yüksek8,8 | — | %1,2 | 23 Şub 2021 |
30İzleyin | CVE-2021-26593İstismar yok | In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}.rangerstudio · directus · CWE-200 | Yüksek7,5 | — | %1,4 | 23 Şub 2021 |
24İzleyin | CVE-2022-24814İstismar yok | Cross-site Scripting in Directusrangerstudio · directus · CWE-79 | Orta6,1 | — | %1,0 | 4 Nis 2022 |
21İzleyin | CVE-2019-13981İstismar yok | In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ dirangerstudio · directus 7 api · CWE-425 | Orta5,3 | — | %1,5 | 19 Tem 2019 |
21İzleyin | CVE-2019-13982İstismar yok | interfaces/markdown/input.vue in Directus 7 Application before 7.7.0 does not sanitize Markdown text before rendering a preview.rangerstudio · directus 7 | Orta5,3 | — | %1,1 | 19 Tem 2019 |
21İzleyin | CVE-2021-27583İstismar yok | In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature.rangerstudio · directus · CWE-203 | Orta5,3 | — | %1,1 | 23 Şub 2021 |
21İzleyin | CVE-2021-26595İstismar yok | In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site,rangerstudio · directus · CWE-312 | Orta5,3 | — | %0,7 | 23 Şub 2021 |
21İzleyin | CVE-2022-22116İstismar yok | Directus - Stored Cross-Site Scripting (XSS) via SVG File Uploadrangerstudio · directus · CWE-79 | Orta5,4 | — | %0,6 | 10 Oca 2022 |
21İzleyin | CVE-2022-22117İstismar yok | Directus - Stored Cross-Site Scripting (XSS) in Profile Avatar Imagerangerstudio · directus · CWE-79 | Orta5,4 | — | %0,6 | 10 Oca 2022 |
21İzleyin | CVE-2023-27474İstismar yok | HTML Injection in Password Reset email to custom Reset URL in directusrangerstudio · directus · CWE-79 | Orta5,4 | — | %0,5 | 6 Mar 2023 |
20İzleyin | CVE-2022-23080İstismar yok | directus - SSRF which leads to internal port scanrangerstudio · directus · CWE-918 | Orta5,0 | — | %0,8 | 22 Haz 2022 |
- CVE-2019-1398339İzleyin
Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php
KritikCVSS 9,8İstismar yokEPSS %1rangerstudio · directus 7 api19 Tem 2019
- CVE-2018-1072339İzleyin
Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.
KritikCVSS 9,8İstismar yokEPSS %1rangerstudio · directus5 May 2018
- CVE-2021-2964136İzleyin
Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include the ability to u
YüksekCVSS 8,8İstismar yokEPSS %5rangerstudio · directus7 Nis 2021
- CVE-2019-1397936İzleyin
In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution.
YüksekCVSS 8,8İstismar yokEPSS %3rangerstudio · directus 7 api19 Tem 2019
- CVE-2019-1398036İzleyin
In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals
YüksekCVSS 8,8İstismar yokEPSS %2rangerstudio · directus 7 api19 Tem 2019
- CVE-2019-1398435İzleyin
Directus 7 API before 2.3.0 does not validate uploaded files.
YüksekCVSS 8,8İstismar yokEPSS %2rangerstudio · directus 7 api19 Tem 2019
- CVE-2021-2659435İzleyin
In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end.
YüksekCVSS 8,8İstismar yokEPSS %1rangerstudio · directus23 Şub 2021
- CVE-2021-2659330İzleyin
In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}.
YüksekCVSS 7,5İstismar yokEPSS %1rangerstudio · directus23 Şub 2021
- CVE-2022-2481424İzleyin
Cross-site Scripting in Directus
OrtaCVSS 6,1İstismar yokEPSS %1rangerstudio · directus4 Nis 2022
- CVE-2019-1398121İzleyin
In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ di
OrtaCVSS 5,3İstismar yokEPSS %2rangerstudio · directus 7 api19 Tem 2019
- CVE-2019-1398221İzleyin
interfaces/markdown/input.vue in Directus 7 Application before 7.7.0 does not sanitize Markdown text before rendering a preview.
OrtaCVSS 5,3İstismar yokEPSS %1rangerstudio · directus 719 Tem 2019
- CVE-2021-2758321İzleyin
In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature.
OrtaCVSS 5,3İstismar yokEPSS %1rangerstudio · directus23 Şub 2021
- CVE-2021-2659521İzleyin
In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site,
OrtaCVSS 5,3İstismar yokEPSS %1rangerstudio · directus23 Şub 2021
- CVE-2022-2211621İzleyin
Directus - Stored Cross-Site Scripting (XSS) via SVG File Upload
OrtaCVSS 5,4İstismar yokEPSS %1rangerstudio · directus10 Oca 2022
- CVE-2022-2211721İzleyin
Directus - Stored Cross-Site Scripting (XSS) in Profile Avatar Image
OrtaCVSS 5,4İstismar yokEPSS %1rangerstudio · directus10 Oca 2022
- CVE-2023-2747421İzleyin
HTML Injection in Password Reset email to custom Reset URL in directus
OrtaCVSS 5,4İstismar yokEPSS %1rangerstudio · directus6 Mar 2023
- CVE-2022-2308020İzleyin
directus - SSRF which leads to internal port scan
OrtaCVSS 5,0İstismar yokEPSS %1rangerstudio · directus22 Haz 2022