Vulnerabilities > Arangodb > Arangodb > 3.4.4

DATE CVE VULNERABILITY TITLE RISK
2021-05-24 CVE-2021-25938 Cross-site Scripting vulnerability in Arangodb
In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to.
network
arangodb CWE-79
4.3