ZeroHour

Vulnerabilities

15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-40500
Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in

Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in the import component.

NVD description · AI analysis pending
8.6<1% PoC
  • scilico i\, librarian
CVE-2023-3021
Cross-site Scripting (XSS) - Stored in GitHub repository mkucej/i-librarian-free prior to 5.10.4.

Cross-site Scripting (XSS) - Stored in GitHub repository mkucej/i-librarian-free prior to 5.10.4.

NVD description · AI analysis pending
5.4<1% PoC
  • scilico i\, librarian
CVE-2023-3020
Cross-site Scripting (XSS) - Reflected in GitHub repository mkucej/i-librarian-free prior to 5.10.4.

Cross-site Scripting (XSS) - Reflected in GitHub repository mkucej/i-librarian-free prior to 5.10.4.

NVD description · AI analysis pending
6.1<1% PoC
  • scilicot i\, librarian
CVE-2019-11428
+1 in the same advisory: …11449
I, Librarian 4.10 has XSS via the export.php export_files parameter.

I, Librarian 4.10 has XSS via the export.php export_files parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • scilico i\, librarian
CVE-2019-11359
Cross-site scripting (XSS) vulnerability in display.php in I, Librarian 4.10 allows remote attackers to inject arbitrary web script or HTML via the project para

Cross-site scripting (XSS) vulnerability in display.php in I, Librarian 4.10 allows remote attackers to inject arbitrary web script or HTML via the project parameter.

NVD description · AI analysis pending
6.11% PoC
  • scilico i\, librarian
CVE-2018-1000138
+3 in the same advisory: …1000141 …1000137 …1000139
I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker abusing fun

I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the server to read or update internal resources.

NVD description · AI analysis pending
9.1
group max
2% PoC
  • scilico i\, librarian
CVE-2018-1000124
I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that

I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via posting xml in the Parameter form_import_textarea.

NVD description · AI analysis pending
10.02% PoC
  • scilico i\, librarian
CVE-2017-1000235
+3 in the same advisory: …1000237 …1000236 …1000234
I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.

I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.

NVD description · AI analysis pending
9.8
group max
3% PoC
  • scilico i\, librarian