CVE-2022-2930
- EPSS 0.35%
- Veröffentlicht 22.08.2022 12:15:09
- Zuletzt bearbeitet 21.11.2024 07:01:56
Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.
CVE-2022-2822
- EPSS 0.82%
- Veröffentlicht 15.08.2022 11:21:32
- Zuletzt bearbeitet 21.11.2024 07:01:45
An attacker can freely brute force username and password and can takeover any account. An attacker could easily guess user passwords and gain access to user and administrative accounts.
CVE-2022-1432
- EPSS 1.21%
- Veröffentlicht 18.05.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:43
Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0.
CVE-2022-1430
- EPSS 1.34%
- Veröffentlicht 18.05.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:43
Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0.
CVE-2021-32561
- EPSS 1.15%
- Veröffentlicht 11.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:16
OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.
CVE-2021-32560
- EPSS 1.5%
- Veröffentlicht 11.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:16
The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not *.log files.
CVE-2018-16710
- EPSS 2.09%
- Veröffentlicht 07.09.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:12
OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: the vendor disputes the significance of this report because their documentation states that with "blind...