WeBankPartners/wecube-platform

WeBankPartners/wecube-platform

Releases45
Frequency1 month 2 weeks
Last Release
Stars381
WeCube Platform

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal plugins.

6.3 MEDIUM

An issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the [Home / Admin / Resources] page, the [Home / Admin / System Params] page, and the [Home / Design / Basekey Configuration] page.

6.1 MEDIUM

An issue was discovered in WeCube platform 3.2.2. A DOM XSS vulnerability has been found on the plugin database execution page.

9.8 CRITICAL7.5 HIGH

An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.

7.5 HIGH5 MEDIUM

A Directory Traversal vulnerability exists in WeBankPartners wecube-platform 3.2.1 via the file variable in PluginPackageController.java.