Filtered by vendor Personal-management-system
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-29319 | 1 Personal-management-system | 1 Personal Management System | 2024-07-09 | N/A | 9.8 CRITICAL |
Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and DNS requests to a server that the attacker controls. | |||||
CVE-2024-29318 | 1 Personal-management-system | 1 Personal Management System | 2024-07-08 | N/A | 5.4 MEDIUM |
Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code. |