RacerZ-fighting/CVE-vulns

RacerZ-fighting/CVE-vulns

Releases0
Stars3

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM

Incorrect access control in the prehandle function of Rebuild v3.7.7 allows attackers to bypass authentication via a crafted GET request sent to /commons/ip-location.

5.1 MEDIUM

Rebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the com.rebuild.web.admin.rbstore.RBStoreController#loadDataIndex method.

8.1 HIGH

An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnerability to access API without any token.