ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-30899
A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories.

A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories.

NVD description · AI analysis pending
4.8<1%
  • partkeepr partkeepr
CVE-2021-39390
Stored XSS in PartKeepr 1.4.0 Edit section in multiple api endpoints via name parameter.

Stored XSS in PartKeepr 1.4.0 Edit section in multiple api endpoints via name parameter.

NVD description · AI analysis pending
5.4<1% PoC
  • partkeepr partkeepr
CVE-2022-22701
+1 in the same advisory: …22702
PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated u

PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local files.

NVD description · AI analysis pending
6.5
group max
1% PoC ×2
  • partkeepr partkeepr