Vulnerabilities (CVE)

Filtered by vendor Personal-management-system Subscribe
Filtered by product Personal Management System
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-29319 1 Personal-management-system 1 Personal Management System 2024-07-09 N/A 9.8 CRITICAL
Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and DNS requests to a server that the attacker controls.
CVE-2024-29318 1 Personal-management-system 1 Personal Management System 2024-07-08 N/A 5.4 MEDIUM
Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code.