Vulnerabilities > Guitar PRO

DATE CVE VULNERABILITY TITLE RISK
2022-11-16 CVE-2022-43263 Cross-site Scripting vulnerability in Guitar-Pro Guitar PRO
A cross-site scripting (XSS) vulnerability in Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the name of an uploaded file.
network
low complexity
guitar-pro CWE-79
6.1
2022-11-16 CVE-2022-43264 Path Traversal vulnerability in Guitar-Pro Guitar PRO
Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download arbitrary files via a crafted web request.
network
low complexity
guitar-pro CWE-22
7.5