Showdoc
showdoc
41 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (41)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SQL Injection in Packagist showdoc/showdoc prior to 2.10.3. |
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2. |
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information |
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
showdoc is vulnerable to URL Redirection to Untrusted Site |
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) |
showdoc is vulnerable to URL Redirection to Untrusted Site |
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions. |
Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdateController.class.php'. |
showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) |
showdoc is vulnerable to Missing Cryptographic Step |
server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team. |
ShowDoc 2.4.1 allows remote attackers to edit other users' notes by navigating with a modified page_id. |
ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discovering a username in the JSON data at a diff URL. |
ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value. |