Day: Kasım 26, 2021


@joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for XSS attacks: a URL for a custom emoji, and…

Devamını oku


Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a malicious actor to trick another user into visiting…

Devamını oku


BaserCMS is an open source content management system with a focus on Japanese language support. In affected versions users with upload privilege may upload crafted…

Devamını oku


There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS. Users with permissions to upload files may…

Devamını oku