Vulnerabilities (CVE)

Filtered by vendor Loklak Project
Filtered by product Loklak
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-15097 1 Loklak Project 1 Loklak 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
loklak is an open-source server application which is able to collect messages from various sources, including twitter. The server contains a search index and a peer-to-peer index sharing interface. All messages are stored in an elasticsearch index. In loklak less than or equal to commit 5f48476, a path traversal vulnerability exists. Insufficient input validation in the APIs exposed by the loklak server allowed a directory traversal vulnerability. Any admin configuration and files readable by th ...

Show More