VYPR
Vendor

Authcrunch

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2024-21496MedFeb 17, 2024
    risk 0.40cvss 6.1epss 0.01

    All versions of the package github.com/greenpau/caddy-security are vulnerable to Cross-site Scripting (XSS) via the Referer header, due to improper input sanitization. Although the Referer header is sanitized by escaping some characters that can allow XSS (e.g., [&], [<], [>],…

  • CVE-2023-52430MedFeb 12, 2024
    risk 0.40cvss 6.1epss 0.00

    The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload and begins with either a /admin or /settings/mfa/delete/ substring.

  • CVE-2024-21498MedFeb 17, 2024
    risk 0.34cvss 5.3epss 0.01

    All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with internal services, or exploit other vulnerabilities within…

  • CVE-2024-21500MedFeb 17, 2024
    risk 0.31cvss 4.8epss 0.01

    All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the user after several failed attempts to provide 2FA codes,…

  • CVE-2024-21492MedFeb 17, 2024
    risk 0.31cvss 4.8epss 0.01

    All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the "Sign Out" button. User sessions remain valid even after requests are sent to /logout and…