VYPR

Onenav

by Helloxz

Source repositories

CVEs (4)

  • CVE-2021-38712HigAug 16, 2021
    risk 0.49cvss 7.5epss 0.01

    OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.

  • CVE-2023-7210HigJan 7, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of the component API. The manipulation of the argument X-Token leads to improper authentication. It is possible to initiate the attack…

  • CVE-2024-33832MedApr 30, 2024
    risk 0.41cvss 6.3epss 0.01

    OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=api&method=get_link_info.

  • CVE-2022-26276MedMar 12, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.