Filtered by vendor Petereport Project
Subscriptions
Filtered by product Petereport
Subscriptions
Total
3 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-25220 | 1 Petereport Project | 1 Petereport | 2024-08-03 | 4.8 Medium |
PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code inside the markdown descriptions while creating a product, report or finding. | ||||
CVE-2022-23051 | 1 Petereport Project | 1 Petereport | 2024-08-03 | 5.4 Medium |
PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack Tree' by modifying the 'svg_file' parameter. | ||||
CVE-2022-23052 | 1 Petereport Project | 1 Petereport | 2024-08-03 | 6.5 Medium |
PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, reports and findings on the application. |
Page 1 of 1.