Vulnerabilities
Vulnerable Software
Gridea:  >> Gridea  Security Vulnerabilities
Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled.
CVSS Score
7.8
EPSS Score
0.0
Published
2022-09-30
Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution, as demonstrated by child_process.exec and the "<img src=# onerror='eval(new Buffer(" substring.
CVSS Score
6.1
EPSS Score
0.004
Published
2019-05-13


Contact Us

Shodan ® - All rights reserved