← Back

Getmedis

getmedis

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Medis
medis

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Getmedis
1Medis
Nov 21, 2024
Jun 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Medis version 0.6.1 and earlier contains a XSS vulnerability evolving into code execution due to enabled nodeIntegration for the renderer process vulnerability in Key name parameter on new key creation that can result in...Show more
Medis version 0.6.1 and earlier contains a XSS vulnerability evolving into code execution due to enabled nodeIntegration for the renderer process vulnerability in Key name parameter on new key creation that can result in Unauthorized code execution in the victim's machine, within the rights of the running application. This attack appear to be exploitable via Victim is synchronizing data from the redis server which contains malicious key value.Show less