Vulnerabilities (CVE)

Filtered by vendor Webswing
Angry Yack Logo
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-39332 1 Webswing 1 Webswing 2025-07-10 N/A 9.8 CRITICAL
Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via modification of shell scripts on the server.
CVE-2022-34914 1 Webswing 1 Webswing 2024-11-21 6.8 MEDIUM 9.8 CRITICAL
Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in the configuration page. The {clientIp} variable can be used as an application startup argument. The X-Forwarded-For header can be manipulated by a client to store an arbitrary value that is used to replace the clientIp variable (without sanitization). A client can thus inject multiple arguments into the session startup. Systems that do not use the clientIP variable in the config ...

Show More

CVE-2020-11103 1 Webswing 1 Webswing 2024-11-21 7.5 HIGH 9.8 CRITICAL
JsLink in Webswing before 2.6.12 LTS, and 2.7.x and 20.x before 20.1, allows remote code execution.