Vulnerabilities
Vulnerable Software
Roothub:  Security Vulnerabilities
A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is the function Edit of the file src/main/java/cn/roothub/web/admin/SystemConfigAdminController.java. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
3.5
EPSS Score
0.0
Published
2025-07-26
Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.
CVSS Score
9.8
EPSS Score
0.002
Published
2024-05-07
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.
CVSS Score
6.3
EPSS Score
0.001
Published
2024-05-07
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function..
CVSS Score
9.8
EPSS Score
0.001
Published
2024-05-07
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function.
CVSS Score
6.3
EPSS Score
0.001
Published
2024-05-06
Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.
CVSS Score
8.0
EPSS Score
0.02
Published
2022-04-13


Contact Us

Shodan ® - All rights reserved