Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-0956: file upload bug · star7th/showdoc@56e450c

Stored XSS via File Upload in GitHub repository star7th/showdoc prior to v.2.10.4.

CVE
#xss#js#git

@@ -329,7 +329,7 @@ public function isAllowedFilename($filename){

'.zip’,’.tar’,’.gz’,’.tgz’,’.ipa’,’.apk’,’.rar’,’.iso’,’.bz2’,’.epub’,

'.pdf’,’.ofd’,’.swf’,’.epub’,’.xps’,

'.doc’,’.docx’,’.odt’,’.rtf’,’.docm’,’.dotm’,’.dot’,’.dotx’,’.wps’,’.wpt’,

'.ppt’,’.pptx’,’.xls’,’.xlsx’,’.txt’,’.md’,’.psd’,’.csv’,

'.ppt’,’.pptx’,’.xls’,’.xlsx’,’.txt’,’.psd’,’.csv’,

'.cer’,’.ppt’,’.pub’,’.properties’,’.json’,’.css’,

) ;

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907