← Back

Springbootmovie

springbootmovie

Vendor: Springbootmovie Project • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Springbootmovie Project
1Springbootmovie
Jun 17, 2026
May 3, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In SpringBootMovie <=1.2, the uploaded file suffix parameter is not filtered, resulting in arbitrary file upload vulnerability
1Springbootmovie Project
1Springbootmovie
Jun 17, 2026
May 3, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In SpringBootMovie <=1.2 when adding movie names, malicious code can be stored because there are no filtering parameters, resulting in stored XSS.