Onenav
by Helloxz
Source repositories
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-38712 | Hig | 0.49 | 7.5 | 0.01 | Aug 16, 2021 | OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file. | ||
| CVE-2023-7210 | Hig | 0.48 | 7.3 | 0.01 | Jan 7, 2024 | A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of the component API. The manipulation of the argument X-Token leads to improper authentication. It is possible to initiate the attack… | ||
| CVE-2024-33832 | Med | 0.41 | 6.3 | 0.01 | Apr 30, 2024 | OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=api&method=get_link_info. | ||
| CVE-2022-26276 | Med | 0.35 | 5.3 | 0.01 | Mar 12, 2022 | An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal. |
- risk 0.49cvss 7.5epss 0.01
OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.
- risk 0.48cvss 7.3epss 0.01
A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of the component API. The manipulation of the argument X-Token leads to improper authentication. It is possible to initiate the attack…
- risk 0.41cvss 6.3epss 0.01
OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=api&method=get_link_info.
- risk 0.35cvss 5.3epss 0.01
An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.