Vulnerabilities > Arangodb > Arangodb > 3.1.5

DATE CVE VULNERABILITY TITLE RISK
2021-05-24 CVE-2021-25938 Cross-site Scripting vulnerability in Arangodb
In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to.
network
low complexity
arangodb CWE-79
6.1