← Back

Yf Exam

yf-exam

Vendor: Yf Exam Project • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yf Exam Project
1Yf Exam
Mar 6, 2025
Mar 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE).
1Yf Exam Project
1Yf Exam
Mar 7, 2025
Mar 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format characters. Any user who logged in within 24 hours. A token can be forged...Show more
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format characters. Any user who logged in within 24 hours. A token can be forged with his username to bypass authentication.Show less
1Yf Exam Project
1Yf Exam
Mar 6, 2025
Mar 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
CleverStupidDog yf-exam 1.8.0 is vulnerable to File Upload. There is no restriction on the suffix of the uploaded file, resulting in any file upload.
1Yf Exam Project
1Yf Exam
Nov 21, 2024
Mar 2, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
CleverStupidDog yf-exam v 1.8.0 is vulnerable to SQL Injection.