Changedetection.io 漏洞列表
共找到 5 个与 Changedetection.io 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2024-34061: Changedetection.io <=v0.45.21 - Cross-Site Scripting POC
Changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. In affected versions Input in parameter notification_urls is not processed resulting in javascript execution in the application. A reflected XSS vulnerability happens when the user input from a URL or POST data is reflected on the page without being stored, thus allowing the attacker to inject malicious content. This issue has been addressed in version 0.45.22. Users are advised to upgrade. There are no known workarounds for this vulnerability. -
CVE-2024-51483: Changedetection.io <= 0.47.4 - Path Traversal POC
changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source-file-///etc/passwd` can be used to retrieve local system files, where the more traditional `file-///etc/passwd` gets blocked. Version 0.47.5 fixes the issue. -
CVE-2024-34061: Changedetection.io <=v0.45.21 - Cross-Site Scripting POC
Changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. In affected versions Input in parameter notification_urls is not processed resulting in javascript execution in the application. A reflected XSS vulnerability happens when the user input from a URL or POST data is reflected on the page without being stored, thus allowing the attacker to inject malicious content. This issue has been addressed in version 0.45.22. Users are advised to upgrade. There are no known workarounds for this vulnerability. -
CVE-2024-51483: Changedetection.io <= 0.47.4 - Path Traversal POC
changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source-file-///etc/passwd` can be used to retrieve local system files, where the more traditional `file-///etc/passwd` gets blocked. Version 0.47.5 fixes the issue. -
changedetection-unauth: Changedetection.io Dashboard - Exposure POC
Changedetection.io unauth panel detected.