VYPR

Kvf Admin

by Kalvingit

CVEs (3)

  • CVE-2022-35857CriJul 13, 2022
    risk 0.64cvss 9.8epss 0.02

    kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. The rememberMe parameter is encrypted with a hardcoded key from the com.kalvin.kvf.common.shiro.ShiroConfig file.

  • CVE-2024-9280MedSep 27, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff and classified as critical. This vulnerability affects the function fileUpload of the file FileUploadKit.java. The manipulation of the argument file leads to unrestricted upload.…

  • CVE-2024-9291LowSep 27, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff. Affected is an unknown function of the file /ueditor/upload?configPath=ueditor/config.json&action=uploadfile of the component XML File Handler. The…