Vulnerabilities
14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-39311 | Publify is a self hosted Web publishing platform on Rails. Publify is a self hosted Web publishing platform on Rails. Prior to version 10.0.1 of Publify, corresponding to versions prior to 10.0.2 of the `publify_core` rubygem, publisher on a `publify` application is able to perform a cross-site scripting (XSS) attack on an administrator using the redirect functionality. The exploitation of this XSS vulnerability requires the administrator to click a malicious link. An attack could attempt to hide their payload by using HTML, or other encodings, as to not make it obvious to an administrator that this is a malicious link. A publisher may attempt to use this vulnerability to escalate their privileges and become an administrator. Version 10.0.1 of Publify and version 10.0.2 of the `publify_core` rubygem fix the issue. NVD description · AI analysis pending | 1.8 | <1% | PoC |
| — | |
| CVE-2023-0569 | Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2022-1812 | Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10. Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10. NVD description · AI analysis pending | 9.8 group max | 31% | PoC |
| — | |
| CVE-2022-1811 +1 in the same advisory: …1810 | Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9. Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9. NVD description · AI analysis pending | 5.4 group max | <1% | PoC |
| — | |
| CVE-2022-0578 | Code Injection in GitHub repository publify/publify prior to 9.2.8. Code Injection in GitHub repository publify/publify prior to 9.2.8. NVD description · AI analysis pending | 6.5 group max | <1% | PoC |
| — | |
| CVE-2022-0524 | Business Logic Errors in GitHub repository publify/publify prior to 9.2.7. Business Logic Errors in GitHub repository publify/publify prior to 9.2.7. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — | |
| CVE-2021-25975 +1 in the same advisory: …25974 | In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2021-25973 | In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only. NVD description · AI analysis pending | 6.5 | <1% |
| — |