Vulnerabilities > Openpsa2

DATE CVE VULNERABILITY TITLE RISK
2018-06-26 CVE-2018-1000526 XML Injection (aka Blind XPath Injection) vulnerability in Openpsa2 Openpsa
Openpsa contains a XML Injection vulnerability in RSS file upload feature that can result in Remote denial of service.
network
low complexity
openpsa2 CWE-91
7.5
2018-06-26 CVE-2018-1000525 Deserialization of Untrusted Data vulnerability in Openpsa2 Openpsa
openpsa contains a PHP Object Injection vulnerability in Form data passed as GET request variables that can result in Possible information disclosure and remote code execution.
network
low complexity
openpsa2 CWE-502
critical
9.8