← Back

Journyx

journyx

4 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Journyx
journyx

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Journyx
1Journyx
Nov 21, 2024
Aug 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwh...Show more
The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.Show less
1Journyx
1Journyx
Nov 21, 2024
Aug 8, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.
1Journyx
1Journyx
Nov 21, 2024
Aug 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.
1Journyx
1Journyx
Nov 21, 2024
Aug 7, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.