By-Yexing/Vulnerability_JAVA

By-Yexing/Vulnerability_JAVA

Releases0
Stars3

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.

5.4 MEDIUM

springboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the suffixes of uploaded files.

5.4 MEDIUM

springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user.

5.4 MEDIUM

springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sysContent/add.

5.4 MEDIUM

springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.