Vulnerabilities > Openpsa2

DATE CVE VULNERABILITY TITLE RISK
2018-06-26 CVE-2018-1000526 XML Injection (aka Blind XPath Injection) vulnerability in Openpsa2 Openpsa
Openpsa contains a XML Injection vulnerability in RSS file upload feature that can result in Remote denial of service.
network
low complexity
openpsa2 CWE-91
5.0
2018-06-26 CVE-2018-1000525 Deserialization of Untrusted Data vulnerability in Openpsa2 Openpsa
openpsa contains a PHP Object Injection vulnerability in Form data passed as GET request variables that can result in Possible information disclosure and remote code execution.
network
low complexity
openpsa2 CWE-502
7.5