CVE-2025-67442
- EPSS 0.7%
- Veröffentlicht 19.12.2025 00:00:00
- Zuletzt bearbeitet 02.01.2026 16:57:55
EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export lab files. This interface lacks effective input validation and filtering when processing file path parameters submitted by users.
CVE-2024-2391
- EPSS 0.11%
- Veröffentlicht 12.03.2024 11:15:49
- Zuletzt bearbeitet 26.02.2025 15:15:08
A vulnerability was found in EVE-NG 5.0.1-13 and classified as problematic. Affected by this issue is some unknown functionality of the component Lab Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The ex...
CVE-2022-31366
- EPSS 1.36%
- Veröffentlicht 20.10.2022 12:15:09
- Zuletzt bearbeitet 08.05.2025 16:15:20
An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file.
- EPSS 5.83%
- Veröffentlicht 04.05.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:56:26
An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attacker to execute commands as root by editing virtualization command para...