Vulnerabilities (CVE)

Filtered by vendor Radixiot Subscribe
Filtered by product Mango
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-37846 1 Radixiot 1 Mango 2024-11-05 N/A 4.6 MEDIUM
MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page.
CVE-2024-37844 1 Radixiot 1 Mango 2024-11-05 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-37847 1 Radixiot 2 Mango, Mangoapi 2024-11-05 N/A 8.8 HIGH
An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted file.
CVE-2024-37845 1 Radixiot 1 Mango 2024-11-04 N/A 7.2 HIGH
MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.