← Back

Repox

repox

Vendor: Europeana • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Europeana
1Repox
Nov 21, 2024
Dec 13, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An unrestricted file upload vulnerability has been identified in Repbox, which allows an attacker to upload malicious files via the transforamationfileupload function, due to the lack of proper file type validation contr...Show more
An unrestricted file upload vulnerability has been identified in Repbox, which allows an attacker to upload malicious files via the transforamationfileupload function, due to the lack of proper file type validation controls, resulting in a full system compromise.Show less
1Europeana
1Repox
Nov 21, 2024
Dec 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A path traversal vulnerability has been detected in Repox, which allows an attacker to read arbitrary files on the running server, resulting in a disclosure of sensitive information. An attacker could access files such a...Show more
A path traversal vulnerability has been detected in Repox, which allows an attacker to read arbitrary files on the running server, resulting in a disclosure of sensitive information. An attacker could access files such as application code or data, backend credentials, operating system files...Show less
1Europeana
1Repox
Nov 21, 2024
Dec 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An XEE vulnerability has been found in Repox, which allows a remote attacker to interfere with the application's XML data processing in the fileupload function, resulting in interaction between the attacker and the serve...Show more
An XEE vulnerability has been found in Repox, which allows a remote attacker to interfere with the application's XML data processing in the fileupload function, resulting in interaction between the attacker and the server's file system.Show less
1Europeana
1Repox
Nov 21, 2024
Dec 13, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An XSS vulnerability stored in Repox has been identified, which allows a local attacker to store a specially crafted JavaScript payload on the server, due to the lack of proper sanitisation of field elements, allowing th...Show more
An XSS vulnerability stored in Repox has been identified, which allows a local attacker to store a specially crafted JavaScript payload on the server, due to the lack of proper sanitisation of field elements, allowing the attacker to trigger the malicious payload when the application loads.Show less
1Europeana
1Repox
Nov 21, 2024
Dec 13, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An XSS vulnerability has been detected in Repox, which allows an attacker to compromise interactions between a user and the vulnerable application, and can be exploited by a third party by sending a specially crafted Jav...Show more
An XSS vulnerability has been detected in Repox, which allows an attacker to compromise interactions between a user and the vulnerable application, and can be exploited by a third party by sending a specially crafted JavaScript payload to a user, and thus gain full control of their session.Show less
1Europeana
1Repox
Nov 21, 2024
Dec 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An authentication bypass vulnerability has been found in Repox, which allows a remote user to send a specially crafted POST request, due to the lack of any authentication method, resulting in the alteration or creation o...Show more
An authentication bypass vulnerability has been found in Repox, which allows a remote user to send a specially crafted POST request, due to the lack of any authentication method, resulting in the alteration or creation of users.Show less