Vulnerabilities (CVE)

Filtered by vendor Linqi Subscribe
Total 6 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-33868 2 Linqi, Microsoft 2 Linqi, Windows 2025-04-28 N/A 9.8 CRITICAL
An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.
CVE-2024-33867 2 Linqi, Microsoft 2 Linqi, Windows 2025-04-28 N/A 4.8 MEDIUM
An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.
CVE-2024-33866 2 Linqi, Microsoft 2 Linqi, Windows 2025-04-28 N/A 5.5 MEDIUM
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.
CVE-2024-33864 2 Linqi, Microsoft 2 Linqi, Windows 2025-04-28 N/A 5.9 MEDIUM
An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file inclusion, and PDF document generation via malicious JavaScript.
CVE-2024-33865 2 Linqi, Microsoft 2 Linqi, Windows 2025-04-28 N/A 7.5 HIGH
An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID] endpoints.
CVE-2024-33863 2 Linqi, Microsoft 2 Linqi, Windows 2025-04-28 N/A 9.8 CRITICAL
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion.