ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-39311
Publify is a self hosted Web publishing platform on Rails.

Publify is a self hosted Web publishing platform on Rails. Prior to version 10.0.1 of Publify, corresponding to versions prior to 10.0.2 of the `publify_core` rubygem, publisher on a `publify` application is able to perform a cross-site scripting (XSS) attack on an administrator using the redirect functionality. The exploitation of this XSS vulnerability requires the administrator to click a malicious link. An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. A publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Version 10.0.1 of Publify and version 10.0.2 of the `publify_core` rubygem fix the issue.

NVD description · AI analysis pending
1.8<1% PoC
  • publify publify
  • publify publify core
CVE-2023-0569
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10.

Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10.

NVD description · AI analysis pending
6.5<1%
  • publify project publify
CVE-2022-1812
+2 in the same advisory: …0299 …2815
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.

Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.

NVD description · AI analysis pending
9.8
group max
31% PoC
  • publify project publify
CVE-2022-1811
+1 in the same advisory: …1810
Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.

Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.

NVD description · AI analysis pending
5.4
group max
<1% PoC
  • publify project publify
CVE-2022-0578
+2 in the same advisory: …0574 …1553
Code Injection in GitHub repository publify/publify prior to 9.2.8.

Code Injection in GitHub repository publify/publify prior to 9.2.8.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • publify project publify
CVE-2022-0524
Business Logic Errors in GitHub repository publify/publify prior to 9.2.7.

Business Logic Errors in GitHub repository publify/publify prior to 9.2.7.

NVD description · AI analysis pending
7.52% PoC
  • publify project publify
CVE-2021-25975
+1 in the same advisory: …25974
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload.

In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file.

NVD description · AI analysis pending
5.4<1%
  • publify project publify
CVE-2021-25973
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control.

In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only.

NVD description · AI analysis pending
6.5<1%
  • publify project publify