Vulnerabilities > Labkey > Labkey Server > 12.1

DATE CVE VULNERABILITY TITLE RISK
2019-01-30 CVE-2019-3913 OS Command Injection vulnerability in Labkey Server
Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker to unmount any drive on the system leading to denial of service.
network
low complexity
labkey CWE-78
4.0
2019-01-30 CVE-2019-3912 Open Redirect vulnerability in Labkey Server
An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary web sites.
network
low complexity
labkey CWE-601
6.1