RSS   Vulnerabilities for 'Springbootmovie'   RSS

2022-05-03
 
CVE-2022-28588

CWE-79
 

 
In SpringBootMovie <=1.2 when adding movie names, malicious code can be stored because there are no filtering parameters, resulting in stored XSS.

 
 
CVE-2022-29001

CWE-434
 

 
In SpringBootMovie <=1.2, the uploaded file suffix parameter is not filtered, resulting in arbitrary file upload vulnerability

 


Copyright 2024, cxsecurity.com

 

Back to Top