VYPR

Yellowfin

by Yellowfinbi

CVEs (3)

  • CVE-2021-36389HigOct 14, 2021
    risk 0.49cvss 7.5epss 0.03

    In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIImage.i4".

  • CVE-2021-36388HigOct 14, 2021
    risk 0.49cvss 7.5epss 0.03

    In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIIAvatarImage.i4".

  • CVE-2021-36387MedOct 14, 2021
    risk 0.35cvss 5.4epss 0.01

    In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially crafted HTTP POST request to the page "ActivityStreamAjax.i4".