B3log
B3log Symphony: vulnerabilidades y CVE
B3log Symphony tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-23049 | Crítica (9.8) | 1.2% | — | 5 feb 2024 | An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component. |
| CVE-2019-17488 | Media (6.1) | 0.82% | — | 10 oct 2019 | b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header. |
| CVE-2018-16249 | Media (4.8) | 0.53% | — | 20 jun 2019 | In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points URI, allowing… |
| CVE-2019-9142 | Media (6.1) | 0.80% | — | 25 feb 2019 | An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java. |
| CVE-2018-10469 | Crítica (9.8) | 2.1% | — | 27 abr 2018 | b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI. |
| CVE-2017-16821 | Media (5.4) | 0.48% | — | 15 nov 2017 | b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP header that is mishandled during display of a client IP address in… |