Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-30899 | A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories. A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2021-39390 | Stored XSS in PartKeepr 1.4.0 Edit section in multiple api endpoints via name parameter. Stored XSS in PartKeepr 1.4.0 Edit section in multiple api endpoints via name parameter. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-22701 +1 in the same advisory: …22702 | PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated u PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local files. NVD description · AI analysis pending | 6.5 group max | 1% | PoC ×2 |
| — |