Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
google rendertron vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2020-8902
Rendertron versions before 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot. Suggested ...
Google Rendertron
7.5
CVSSv3
CVE-2017-18354
Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.
Google Rendertron 1.0.0
7.5
CVSSv3
CVE-2017-18353
Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote malicious user to disable the core service of the application.
Google Rendertron 1.0.0
7.5
CVSSv3
CVE-2017-18355
Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote malicious users to read absolute paths on the server by examining the "_where" attribute of package.json files.
Google Rendertron 1.0.0
6.1
CVSSv3
CVE-2017-18352
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.
Google Rendertron 1.0.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27802
template injection
CVE-2024-0044
code injection
CVE-2024-35474
CVE-2024-27857
CVE-2024-23251
CVE-2024-23692
physical
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started