Vulnerabilities > Nbnbk Project > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-12-23 | CVE-2022-46492 | Path Traversal vulnerability in Nbnbk Project Nbnbk nbnbk commit 879858451d53261d10f77d4709aee2d01c72c301 was discovered to contain an arbitrary file read vulnerability via the component /api/Index/getFileBinary. | 6.5 |
2022-12-22 | CVE-2022-46491 | Cross-Site Request Forgery (CSRF) vulnerability in Nbnbk Project Nbnbk A Cross-Site Request Forgery (CSRF) vulnerability in the Add Administrator function of the default version of nbnbk allows attackers to arbitrarily add Administrator accounts. | 6.5 |