VYPR

by Sharelatex

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2015-09340.000.02Mar 4, 2015Common LaTeX Service Interface (CLSI) before 0.1.3, as used in ShareLaTeX before 0.1.3, allows remote authenticated users to execute arbitrary code via ` (backtick) characters in a filename.
CVE-2015-09330.000.00Mar 4, 2015Absolute path traversal vulnerability in ShareLaTeX 0.1.3 and earlier, when the paranoid openin_any setting is omitted, allows remote authenticated users to read arbitrary files via a \include command.