Europeana
Europeana Repox: vulnerabilidades y CVE
Europeana Repox tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-6723 | Crítica (9.8) | 0.78% | — | 13 dic 2023 | An unrestricted file upload vulnerability has been identified in Repbox, which allows an attacker to upload malicious files via the transforamationfileupload function, due to the lack of proper file type validation… |
| CVE-2023-6722 | Alta (7.5) | 0.83% | — | 13 dic 2023 | A path traversal vulnerability has been detected in Repox, which allows an attacker to read arbitrary files on the running server, resulting in a disclosure of sensitive information. An attacker could access files such… |
| CVE-2023-6721 | Alta (7.5) | 0.60% | — | 13 dic 2023 | An XEE vulnerability has been found in Repox, which allows a remote attacker to interfere with the application's XML data processing in the fileupload function, resulting in interaction between the attacker and the… |
| CVE-2023-6720 | Media (5.4) | 0.37% | — | 13 dic 2023 | An XSS vulnerability stored in Repox has been identified, which allows a local attacker to store a specially crafted JavaScript payload on the server, due to the lack of proper sanitisation of field elements, allowing… |
| CVE-2023-6719 | Media (6.1) | 0.41% | — | 13 dic 2023 | An XSS vulnerability has been detected in Repox, which allows an attacker to compromise interactions between a user and the vulnerable application, and can be exploited by a third party by sending a specially crafted… |
| CVE-2023-6718 | Alta (7.5) | 0.85% | — | 13 dic 2023 | An authentication bypass vulnerability has been found in Repox, which allows a remote user to send a specially crafted POST request, due to the lack of any authentication method, resulting in the alteration or creation… |