freetakserver-ui
PyPI4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting freetakserver-uipage 1 of 1
- CVE-2022-25506MEDIUMCVSS 6.5EG 6.52022-03-11
vulnerable: 0.1.0 ... 1.9.8 (21 versions)
FreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser.
- CVE-2022-25507MEDIUMCVSS 5.4EG 5.42022-03-11
vulnerable: 0.1.0 ... 1.9.8 (21 versions)
FreeTAKServer-UI v1.9.8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Callsign parameter.
- CVE-2022-25511MEDIUMCVSS 6.5EG 6.52022-03-11
vulnerable: 0.1.0 ... 1.9.8 (21 versions)
An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbitrary files anywhere on the system.
- CVE-2022-25512HIGHCVSS 7.5EG 7.52022-03-11
vulnerable: 0.1.0 ... 1.9.8 (21 versions)
FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys.
Check whether freetakserver-ui is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for freetakserver-ui CVEs against the assets you own.
Start Free Scan →