Lucene search

K

Personal Management System Security Vulnerabilities

cve
cve

CVE-2023-43838

An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.

7.8CVSS

7.8AI Score

0.001EPSS

2023-10-04 04:15 PM
24
cve
cve

CVE-2024-29318

Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code.

5.4CVSS

5.9AI Score

0.0004EPSS

2024-07-05 04:15 PM
27
cve
cve

CVE-2024-29319

Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and DNS requests to a server that the attacker controls.

9.8CVSS

7AI Score

0.001EPSS

2024-07-05 04:15 PM
26