Vulnerabilities
Vulnerable Software
Lfedge:  >> Ekuiper  >> 0.0.2  Security Vulnerabilities
LF Edge eKuiper is a lightweight internet of things (IoT) data analytics and stream processing engine. Prior to version 2.1.0 user with rights to modificate the service (e.g. kuiperUser role) can inject a cross-site scripting payload into Connection Configuration key `Name` (`confKey`) parameter. After this setup, when any user with access to this service (e.g. admin) tries to delete this key, a payload acts in the victim's browser. Version 2.1.0 fixes the issue.
CVSS Score
6.3
EPSS Score
0.0
Published
2025-05-14
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.
CVSS Score
8.8
EPSS Score
0.006
Published
2024-08-20


Contact Us

Shodan ® - All rights reserved