Vulnerabilities > Guitar PRO

DATE CVE VULNERABILITY TITLE RISK
2022-11-16 CVE-2022-43263 Cross-site Scripting vulnerability in Guitar-Pro Guitar PRO
A cross-site scripting (XSS) vulnerability in Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the name of an uploaded file.
network
low complexity
guitar-pro CWE-79
6.1
2022-11-16 CVE-2022-43264 Path Traversal vulnerability in Guitar-Pro Guitar PRO
Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download arbitrary files via a crafted web request.
network
low complexity
guitar-pro CWE-22
7.5
2012-11-27 CVE-2012-6048 Buffer Errors vulnerability in Guitar-Pro Guitar PRO 6.1.1
Guitar Pro 6.1.1 r10791 allows remote attackers to cause a denial of service (crash) via a long string in a gpx file.
network
low complexity
guitar-pro CWE-119
5.0