Vulnerabilities > Skinsoft

DATE CVE VULNERABILITY TITLE RISK
2024-02-22 CVE-2024-25802 Unrestricted Upload of File with Dangerous Type vulnerability in Skinsoft S-Museum 7.02.3
SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function.
network
low complexity
skinsoft CWE-434
critical
9.8
2024-02-22 CVE-2024-25801 Cross-site Scripting vulnerability in Skinsoft S-Museum 7.02.3
SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file.
network
low complexity
skinsoft CWE-79
6.1