VYPR
Vendor

Antsword Project

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2020-18766CriOct 26, 2020
    risk 0.62cvss 9.6epss 0.01

    A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands.

  • CVE-2020-25470MedOct 26, 2020
    risk 0.40cvss 6.1epss 0.01

    AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion. When viewing an added site, an XSS payload can be injected in cookies view which can lead to remote code execution.

  • CVE-2019-13970MedJul 19, 2019
    risk 0.33cvss 6.1epss 0.02

    In antSword before 2.1.0, self-XSS in the database configuration leads to code execution via modules/database/asp/index.js, modules/database/custom/index.js, modules/database/index.js, or modules/database/php/index.js.