CVE-2022-31189
- EPSS 0.23%
- Veröffentlicht 01.08.2022 21:15:13
- Zuletzt bearbeitet 21.11.2024 07:04:05
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. When an "Internal System Error" occurs in the JSPUI, then entire exception (including stack trace) ...
CVE-2022-31191
- EPSS 0.44%
- Veröffentlicht 01.08.2022 21:15:13
- Zuletzt bearbeitet 21.11.2024 07:04:05
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI spellcheck "Did you mean" HTML escapes the data-spell attribute in the link, but not the ...
CVE-2022-31192
- EPSS 0.32%
- Veröffentlicht 01.08.2022 21:15:13
- Zuletzt bearbeitet 21.11.2024 07:04:05
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI "Request a Copy" feature does not properly escape values submitted and stored from the "R...
CVE-2022-31193
- EPSS 0.26%
- Veröffentlicht 01.08.2022 21:15:13
- Zuletzt bearbeitet 21.11.2024 07:04:05
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI controlled vocabulary servlet is vulnerable to an open redirect attack, where an attacker...
CVE-2022-31194
- EPSS 0.83%
- Veröffentlicht 01.08.2022 21:15:13
- Zuletzt bearbeitet 21.11.2024 07:04:05
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI resumable upload implementations in SubmissionController and FileUploadRequest are vulner...
CVE-2022-31195
- EPSS 0.83%
- Veröffentlicht 01.08.2022 21:15:13
- Zuletzt bearbeitet 21.11.2024 07:04:06
DSpace open source software is a repository application which provides durable access to digital resources. In affected versions the ItemImportServiceImpl is vulnerable to a path traversal vulnerability. This means a malicious SAF (simple archive for...
CVE-2022-31190
- EPSS 0.26%
- Veröffentlicht 01.08.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:05
DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata on a withdrawn Item is exposed via the XMLUI "mets.xml" object, as lo...
- EPSS 0.63%
- Veröffentlicht 29.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:25:43
DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up to become system administrator. This vulnerability only exists in 7.0 and does not impact 6.x or below...
CVE-2016-10726
- EPSS 0.15%
- Veröffentlicht 10.07.2018 11:29:00
- Zuletzt bearbeitet 21.11.2024 02:44:36
The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack with two or more arbitrary characters and a colon before a pathname, as demonstrated by a themes/Reference/aa:etc/...