Ymfe

Yapi

4 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Published 30.04.2024 18:15:19
  • Last modified 21.11.2024 09:17:33

A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the body field.

Exploit
  • EPSS 0.27%
  • Published 26.01.2023 21:15:24
  • Last modified 01.04.2025 14:15:15

Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page.

  • EPSS 0.06%
  • Published 01.03.2021 23:15:13
  • Last modified 21.11.2024 05:58:41

Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens. This occurs because Math.random in Node.js is used.

Exploit
  • EPSS 0.21%
  • Published 28.09.2018 09:29:00
  • Last modified 21.11.2024 03:54:38

An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.