twonav
by twonav
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-29450 | Med | 0.42 | 6.5 | 0.00 | Apr 17, 2025 | An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings component. | ||
| CVE-2025-29449 | Med | 0.42 | 6.5 | 0.00 | Apr 17, 2025 | An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identification function. | ||
| CVE-2023-37657 | Med | 0.35 | 5.4 | 0.00 | Jul 11, 2023 | TwoNav v2.0.28-20230624 is vulnerable to Cross Site Scripting (XSS). | ||
| CVE-2024-34453 | Med | 0.28 | 4.3 | 0.00 | May 3, 2024 | TwoNav 2.1.13 contains an SSRF vulnerability via the url paramater to index.php?c=api&method=read_data&type=connectivity_test (which reaches /system/api.php). |
- risk 0.42cvss 6.5epss 0.00
An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings component.
- risk 0.42cvss 6.5epss 0.00
An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identification function.
- risk 0.35cvss 5.4epss 0.00
TwoNav v2.0.28-20230624 is vulnerable to Cross Site Scripting (XSS).
- risk 0.28cvss 4.3epss 0.00
TwoNav 2.1.13 contains an SSRF vulnerability via the url paramater to index.php?c=api&method=read_data&type=connectivity_test (which reaches /system/api.php).