Vulnerabilities > Cesanta > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-09-07 | CVE-2017-11567 | Cross-Site Request Forgery (CSRF) vulnerability in Cesanta Mongoose Embedded web Server Library Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save. | 6.8 |
2017-04-10 | CVE-2017-7185 | Use After Free vulnerability in Cesanta Mongoose Embedded web Server Library and Mongoose OS Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary string. | 5.0 |