Vulnerabilities
Vulnerable Software
Usvn:  >> Usvn  >> 1.0.2  Security Vulnerabilities
USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or number_end parameter to LastHundredRequest (aka lasthundredrequestAction) in the Timeline module. NOTE: this may overlap CVE-2020-25069.
CVSS Score
9.9
EPSS Score
0.067
Published
2020-12-31
USVN (aka User-friendly SVN) before 1.0.10 allows attackers to execute arbitrary code in the commit view.
CVSS Score
9.8
EPSS Score
0.011
Published
2020-09-01
USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature.
CVSS Score
8.8
EPSS Score
0.002
Published
2020-09-01
Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-11-15


Contact Us

Shodan ® - All rights reserved