Vulnerabilities > Simiki Project

DATE CVE VULNERABILITY TITLE RISK
2021-08-27 CVE-2020-19000 Cross-site Scripting vulnerability in Simiki Project Simiki 1.6.2.1
Cross Site Scripting (XSS) in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary code via line 54 of the component 'simiki/blob/master/simiki/generators.py'.
4.3
2021-08-27 CVE-2020-19001 Command Injection vulnerability in Simiki Project Simiki 1.6.2.1
Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/master/simiki/config.py'.
network
low complexity
simiki-project CWE-77
critical
10.0