VYPR

Lin CMS Flask

by TaleLin

CVEs (3)

  • CVE-2020-18701CriAug 16, 2021
    risk 0.64cvss 9.8epss 0.02

    Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.

  • CVE-2020-18698CriAug 16, 2021
    risk 0.64cvss 9.8epss 0.02

    Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.

  • CVE-2020-18699MedAug 16, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'.