Vulnerabilities > Radixiot > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-10-25 CVE-2024-37844 Cross-site Scripting vulnerability in Radixiot Mango
A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
network
low complexity
radixiot CWE-79
5.4
2024-10-25 CVE-2024-37846 Code Injection vulnerability in Radixiot Mango
MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page.
network
low complexity
radixiot CWE-94
4.6