Filtered by vendor Webswing
Subscribe
Total
3 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-39332 | 1 Webswing | 1 Webswing | 2025-07-10 | N/A | 9.8 CRITICAL |
|
Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via modification of shell scripts on the server.
|
|||||
| CVE-2022-34914 | 1 Webswing | 1 Webswing | 2024-11-21 | 6.8 MEDIUM | 9.8 CRITICAL |
|
Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in the configuration page. The {clientIp} variable can be used as an application startup argument. The X-Forwarded-For header can be manipulated by a client to store an arbitrary value that is used to replace the clientIp variable (without sanitization). A client can thus inject multiple arguments into the session startup. Systems that do not use the clientIP variable in the config ...
Show More |
|||||
| CVE-2020-11103 | 1 Webswing | 1 Webswing | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
JsLink in Webswing before 2.6.12 LTS, and 2.7.x and 20.x before 20.1, allows remote code execution.
|
|||||