OpenCATS 漏洞列表
共找到 9 个与 OpenCATS 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2022-43014: OpenCATS 0.9.6 - Cross-Site Scripting POC
OpenCATS 0.9.6 contains a cross-site scripting vulnerability via the joborderID parameter. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. -
CVE-2022-43015: OpenCATS 0.9.6 - Cross-Site Scripting POC
OpenCATS 0.9.6 contains a cross-site scripting vulnerability via the entriesPerPage parameter. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. -
CVE-2022-43016: OpenCATS 0.9.6 - Cross-Site Scripting POC
OpenCATS 0.9.6 contains a cross-site scripting vulnerability via the callback component. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. -
CVE-2022-43017: OpenCATS 0.9.6 - Cross-Site Scripting POC
OpenCATS 0.9.6 contains a cross-site scripting vulnerability via the indexFile component. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. -
CVE-2022-43018: OpenCATS 0.9.6 - Cross-Site Scripting POC
OpenCATS 0.9.6 contains a cross-site scripting vulnerability via the email parameter in the Check Email function. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. -
CVE-2022-48012: OpenCATS 0.9.7 - Cross-Site Scripting POC
OpenCATS 0.9.7 contains a cross-site scripting vulnerability via the component /opencats/index.php?m=settings&a=ajax_tags_upd. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site, which can allow the attacker to steal cookie-based authentication credentials and launch other attacks. -
CVE-2023-27292: OpenCATS - Open Redirect POC
OpenCATS contains an open redirect vulnerability due to improper validation of user-supplied GET parameters. This, in turn, exposes OpenCATS to possible template injection and obtaining sensitive information, modifying data, and/or executing unauthorized operations. -
OpenCATS反射型跨站脚本漏洞 无POC
OpenCATS存在反射型跨站脚本漏洞,此漏洞是由于缺乏验证导致的。 -
OpenCATS Calendar Event CVE-2023-27294 存储型跨站脚本漏洞 无POC