Filtered by vendor Personal-management-system Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-43838 1 Personal-management-system 1 Personal Management System 2024-09-20 7.8 High
An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.
CVE-2024-29318 1 Personal-management-system 1 Personal Management System 2024-08-02 5.4 Medium
Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code.
CVE-2024-29319 1 Personal-management-system 1 Personal Management System 2024-08-02 9.8 Critical
Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and DNS requests to a server that the attacker controls.