VYPR

Firefly Iii/firefly Iii

by Firefly Iii

Source repositories

CVEs (24)

  • CVE-2019-14670MedAug 5, 2019
    risk 0.00cvss 5.4epss 0.01

    Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is executed during rule-from-bill creation.

  • CVE-2019-14669MedAug 5, 2019
    risk 0.00cvss 5.4epss 0.01

    Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code is executed during a visit to the audit account statistics page.

  • CVE-2019-14668MedAug 5, 2019
    risk 0.00cvss 5.4epss 0.01

    Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction description field. The JavaScript code is executed during deletion of a transaction link.

  • CVE-2019-14667MedAug 5, 2019
    risk 0.00cvss 6.1epss 0.01

    Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name. The JavaScript code is executed during a convert transaction action.

Page 2 of 2