Security Vulnerabilities
- CVEs Published In February 2022
This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL file. This issue affects: Bitdefender Antivirus Plus versions prior to 24.0.26.136. Bitdefender Internet Security versions prior to 24.0.26.136. Bitdefender Total Security versions prior to 24.0.26.136.
An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description.
An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups.
An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled.
An issue was discovered in Cerebrate through 1.4. Username enumeration could occur.
An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.