Nbnbk Project
Nbnbk Project Nbnbk: vulnerabilidades y CVE
Nbnbk Project Nbnbk tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-46492 | Media (6.5) | 0.50% | — | 23 dic 2022 | nbnbk commit 879858451d53261d10f77d4709aee2d01c72c301 was discovered to contain an arbitrary file read vulnerability via the component /api/Index/getFileBinary. |
| CVE-2022-46493 | Crítica (9.8) | 0.82% | — | 22 dic 2022 | Default version of nbnbk was discovered to contain an arbitrary file upload vulnerability via the component /api/User/download_img. |
| CVE-2022-46491 | Media (6.5) | 0.28% | — | 22 dic 2022 | A Cross-Site Request Forgery (CSRF) vulnerability in the Add Administrator function of the default version of nbnbk allows attackers to arbitrarily add Administrator accounts. |
| CVE-2022-31386 | Crítica (9.1) | 1.0% | — | 9 jun 2022 | A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the URL parameter. |