Vulnerabilities > Onekeyadmin

DATE CVE VULNERABILITY TITLE RISK
2023-03-16 CVE-2023-26951 Cross-site Scripting vulnerability in Onekeyadmin 1.3.9
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Member List module.
network
low complexity
onekeyadmin CWE-79
5.4
2023-03-09 CVE-2023-26957 Missing Authorization vulnerability in Onekeyadmin 1.3.9
onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins.
network
low complexity
onekeyadmin CWE-862
critical
9.1
2023-03-09 CVE-2023-26948 Files or Directories Accessible to External Parties vulnerability in Onekeyadmin 1.3.9
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/download.
network
low complexity
onekeyadmin CWE-552
7.5
2023-03-08 CVE-2023-26956 Files or Directories Accessible to External Parties vulnerability in Onekeyadmin 1.3.9
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code.
network
low complexity
onekeyadmin CWE-552
7.5
2023-03-08 CVE-2023-26952 Cross-site Scripting vulnerability in Onekeyadmin 1.3.9
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Menu module.
network
low complexity
onekeyadmin CWE-79
5.4
2023-03-08 CVE-2023-26950 Cross-site Scripting vulnerability in Onekeyadmin 1.3.9
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Title parameter under the Adding Categories module.
network
low complexity
onekeyadmin CWE-79
5.4
2023-03-07 CVE-2023-26953 Cross-site Scripting vulnerability in Onekeyadmin 1.3.9
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Administrator module.
network
low complexity
onekeyadmin CWE-79
4.8
2023-03-06 CVE-2023-26949 Unrestricted Upload of File with Dangerous Type vulnerability in Onekeyadmin 1.3.9
An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
onekeyadmin CWE-434
critical
9.8