Vulnerabilities > Http Swagger Project
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-29 | CVE-2024-25712 | Cross-site Scripting vulnerability in Http-Swagger Project Http-Swagger http-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandler and *webdav.memFile) can subsequently be accessed via a GET request. | 6.1 |
2022-04-18 | CVE-2022-24863 | Improper Handling of Exceptional Conditions vulnerability in Http-Swagger Project Http-Swagger http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. | 7.5 |