Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
opencats opencats vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2021-25295
OpenCATS up to and including 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.
Opencats Opencats
9.8
CVSSv3
CVE-2021-25294
OpenCATS up to and including 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the parametersactivity:ActivityDataGrid parameter. The PHP object injection exploit chain can lev...
Opencats Opencats
9.8
CVSSv3
CVE-2021-41560
OpenCATS up to and including 0.9.6 allows remote malicious users to execute arbitrary code by uploading an executable file via lib/FileUtility.php.
Opencats Opencats
1 Github repository
7.5
CVSSv3
CVE-2019-13358
lib/DocumentToText.php in OpenCats prior to 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.
Opencats Opencats
3 Github repositories
6.1
CVSSv3
CVE-2022-43015
OpenCATS v0.9.6 exists to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.
Opencats Opencats 0.9.6
9.8
CVSSv3
CVE-2022-43019
OpenCATS v0.9.6 exists to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.
Opencats Opencats 0.9.6
6.5
CVSSv3
CVE-2022-43021
OpenCATS v0.9.6 exists to contain a SQL injection vulnerability via the entriesPerPage variable.
Opencats Opencats 0.9.6
6.1
CVSSv3
CVE-2023-27293
Improper neutralization of input during web page generation allows an unauthenticated malicious user to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission. This could be used...
Opencats Opencats 0.9.6
5.4
CVSSv3
CVE-2023-27295
Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can exploit this issue by creating a dummy page that executes Javascript in an authenticated user's session when visited.
Opencats Opencats 0.9.6
6.1
CVSSv3
CVE-2022-43017
OpenCATS v0.9.6 exists to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.
Opencats Opencats 0.9.6
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »