VYPR

Peppermint

by Peppermint

CVEs (4)

  • CVE-2023-42328HigSep 18, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie.

  • CVE-2023-26984HigMar 29, 2023
    risk 0.53cvss 8.1epss 0.01

    An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted request.

  • CVE-2023-46863HigOct 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Peppermint Ticket Management before 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/users/file/download?filepath=./../ POST request.

  • CVE-2023-46864MedOct 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/download?filepath=../ POST request.