Vulnerabilities
Vulnerable Software
firefly-iii is vulnerable to URL Redirection to Untrusted Site
CVSS Score
5.0
EPSS Score
0.002
Published
2021-10-19
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVSS Score
4.3
EPSS Score
0.001
Published
2021-09-27
firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts
CVSS Score
5.3
EPSS Score
0.002
Published
2021-07-25
Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name. The JavaScript code is contained in a transaction, and is executed on the tags/show/$tag_number$ tag summary page. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability
CVSS Score
5.4
EPSS Score
0.002
Published
2019-07-18
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file names. The JavaScript code is executed during attachments/edit/$file_id$ attachment editing. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability
CVSS Score
5.4
EPSS Score
0.002
Published
2019-07-18
Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search query. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability
CVSS Score
5.4
EPSS Score
0.002
Published
2019-07-18
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content. The JavaScript code is executed during attachments/view/$file_id$ attachment viewing. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability
CVSS Score
5.4
EPSS Score
0.002
Published
2019-07-18


Contact Us

Shodan ® - All rights reserved