FreeTAKTeam/UI

FreeTAKTeam/UI

Releases10
Frequency4 months 2 weeks
Last Release
Stars41
FreeTAKServer Web User Interface project

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM4 MEDIUM

FreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser.

5.4 MEDIUM3.5 LOW

FreeTAKServer-UI v1.9.8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Callsign parameter.

6.5 MEDIUM4 MEDIUM

An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbitrary files anywhere on the system.

7.5 HIGH5 MEDIUM

FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys.