BuffaloWill/Serpico

BuffaloWill/Serpico

Releases17
Frequency2 months 3 weeks
Last Release
Stars1.11K
SimplE RePort wrIting and COllaboration tool

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM4 MEDIUM

An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin authenticated users. This means that an attacker with a user account can retrieve all of the attachments of all users (including administrators) from the database.

4.8 MEDIUM3.5 LOW

An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/list_user allows stored XSS via the auth_type parameter.

4.8 MEDIUM3.5 LOW

An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The User Type on the admin/list_user page allows stored XSS via the type parameter.

4.8 MEDIUM3.5 LOW

An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/add_user/UID allows stored XSS via the author parameter.