VYPR

sims

by rawchen

CVEs (3)

  • CVE-2022-34549HigJul 27, 2022
    risk 0.57cvss 8.8epss 0.01

    Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows attackers to escalate privileges and execute arbitrary commands via a crafted file.

  • CVE-2022-34551MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.01

    Sims v1.0 was discovered to allow path traversal when downloading attachments.

  • CVE-2026-7024MedApr 26, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unknown functionality of the file sims-master/src/web/servlet/file/DeleteFileServlet.java of the component deleteFileServlet Endpoint. Executing a manipulation of…