VYPR

SphinxSearch

by Sphinx Technologies

CVEs (2)

  • CVE-2020-29050HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.02

    SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). NOTE: this is…

  • CVE-2019-14511HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.02

    Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).