
mkucej/i-librarian
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 9.8 CRITICAL | — | ||
i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php. | |||
| — | 4.3 MEDIUM | ||
I, Librarian 4.10 has XSS via the notes.php notes parameter. | |||
| — | 4.3 MEDIUM | ||
I, Librarian 4.10 has XSS via the export.php export_files parameter. | |||
| — | 4.3 MEDIUM | ||
Cross-site scripting (XSS) vulnerability in display.php in I, Librarian 4.10 allows remote attackers to inject arbitrary web script or HTML via the project parameter. | |||
| 8.8 HIGH | 6.8 MEDIUM | ||
I, Librarian version 4.8 and earlier contains a Cross site Request Forgery (CSRF) vulnerability in users.php that can result in the password of the admin being forced to be changed without the administrator's knowledge. | |||
| 9.1 CRITICAL | 6.4 MEDIUM | ||
I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the server to read or update internal resources. | |||
| 6.1 MEDIUM | 4.3 MEDIUM | ||
I, Librarian version 4.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in "id" parameter in stable.php that can result in an attacker using the XSS to send a malicious script to an unsuspecting user. | |||
| 9.1 CRITICAL | 7.5 HIGH | ||
I, Librarian version 4.9 and earlier contains an Incorrect Access Control vulnerability in ajaxdiscussion.php that can result in any users gaining unauthorized access (read, write and delete) to project discussions. | |||
| 10 CRITICAL | 7.5 HIGH | ||
I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via posting xml in the Parameter form_import_textarea. | |||