Vulnerabilities > Radixiot

DATE CVE VULNERABILITY TITLE RISK
2024-10-25 CVE-2024-37844 Cross-site Scripting vulnerability in Radixiot Mango
A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
network
low complexity
radixiot CWE-79
5.4
2024-10-25 CVE-2024-37845 OS Command Injection vulnerability in Radixiot Mango
MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.
network
low complexity
radixiot CWE-78
7.2
2024-10-25 CVE-2024-37846 Code Injection vulnerability in Radixiot Mango
MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page.
network
low complexity
radixiot CWE-94
4.6
2024-10-25 CVE-2024-37847 Path Traversal vulnerability in Radixiot Mango and Mangoapi
An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted file.
network
low complexity
radixiot CWE-22
8.8