← Back

Onenav

onenav

6 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Onenav
onenav

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Onenav
1Onenav
Apr 7, 2025
Mar 28, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.
1Onenav
1Onenav
Apr 7, 2025
Mar 28, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.
1Onenav
1Onenav
Nov 21, 2024
Jan 7, 2024
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of the component API. The manipulation of the argument X-Token leads to impr...Show more
A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of the component API. The manipulation of the argument X-Token leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249765 was assigned to this vulnerability.Show less
1Onenav
1Onenav
Nov 21, 2024
Mar 12, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.
1Onenav
1Onenav
Nov 21, 2024
Aug 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.
1Onenav
1Onenav
Nov 21, 2024
Aug 5, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XSS protection at present, because the attack risk is largely limited to a compromised account; h...Show more
OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XSS protection at present, because the attack risk is largely limited to a compromised account; however, XSS protection is planned for a future release.Show less