Ss-proj

Shirasagi

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.93%
  • Veröffentlicht 15.10.2024 07:15:02
  • Zuletzt bearbeitet 17.10.2024 17:52:00

SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the server may be retrieved when processing crafted HTTP requests.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 15.09.2023 21:15:11
  • Zuletzt bearbeitet 21.11.2024 08:21:51

SHIRASAGI is a Content Management System. Prior to version 1.18.0, SHIRASAGI is vulnerable to a Post-Unicode normalization issue. This happens when a logical validation or a security check is performed before a Unicode normalization. The Unicode char...

  • EPSS 0.68%
  • Veröffentlicht 05.09.2023 10:15:07
  • Zuletzt bearbeitet 21.11.2024 08:09:49

Reflected cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.

  • EPSS 0.33%
  • Veröffentlicht 05.09.2023 10:15:07
  • Zuletzt bearbeitet 21.11.2024 08:13:50

Stored cross-site scripting vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.

  • EPSS 4.73%
  • Veröffentlicht 05.09.2023 09:15:08
  • Zuletzt bearbeitet 21.11.2024 08:15:26

Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create arbitrary files on the server, resulting in arbitrary code execution.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 24.02.2023 06:15:11
  • Zuletzt bearbeitet 12.03.2025 16:15:19

Stored cross-site scripting vulnerability in Schedule function of SHIRASAGI v1.16.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 24.02.2023 06:15:11
  • Zuletzt bearbeitet 12.03.2025 16:15:19

Stored cross-site scripting vulnerability in Theme switching function of SHIRASAGI v1.16.2 and earlier versions allows a remote attacker with an administrative privilege to inject an arbitrary script.

Exploit
  • EPSS 0.64%
  • Veröffentlicht 05.12.2022 04:15:10
  • Zuletzt bearbeitet 24.04.2025 15:15:51

Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and conduct a phishing attack.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 05.12.2022 04:15:10
  • Zuletzt bearbeitet 24.04.2025 14:15:37

Stored cross-site scripting vulnerability in SHIRASAGI versions prior to v1.16.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.

  • EPSS 0.4%
  • Veröffentlicht 14.06.2022 09:15:09
  • Zuletzt bearbeitet 21.11.2024 06:59:10

Cross-site scripting vulnerability in SHIRASAGI v1.0.0 to v1.14.2, and v1.15.0 allows a remote attacker to inject an arbitrary script via unspecified vectors.