Vulnerabilities
Vulnerable Software
Yf-Exam Project:  >> Yf-Exam  Security Vulnerabilities
CleverStupidDog yf-exam 1.8.0 is vulnerable to File Upload. There is no restriction on the suffix of the uploaded file, resulting in any file upload.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-03-03
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format characters. Any user who logged in within 24 hours. A token can be forged with his username to bypass authentication.
CVSS Score
7.5
EPSS Score
0.0
Published
2023-03-03
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE).
CVSS Score
9.8
EPSS Score
0.01
Published
2023-03-03
CleverStupidDog yf-exam v 1.8.0 is vulnerable to SQL Injection.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-03-02


Contact Us

Shodan ® - All rights reserved