ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-9926
+2 in the same advisory: …9757 …9758
An issue was discovered in LabKey Server 19.1.0.

An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a /reports-viewScriptReport.view CSRF vulnerability.

NVD description · AI analysis pending
8.8
group max
2% PoC ×2
  • labkey labkey server
CVE-2019-3912
+2 in the same advisory: …3911 …3913
An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote at

An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary web sites.

NVD description · AI analysis pending
6.1
group max
5% PoC
  • labkey labkey server