Vulnerabilities > Talelin

DATE CVE VULNERABILITY TITLE RISK
2024-07-19 CVE-2024-41600 Unspecified vulnerability in Talelin Lin-Cms-Spring-Boot 0.2.0/0.2.1
Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.
network
low complexity
talelin
7.5
2022-07-21 CVE-2022-32430 Unspecified vulnerability in Talelin Lin-Cms-Spring-Boot 0.2.1
An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.
network
low complexity
talelin
7.5
2021-08-16 CVE-2020-18698 Improper Restriction of Excessive Authentication Attempts vulnerability in Talelin Lin-Cms-Flask 0.1.1
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.
network
low complexity
talelin CWE-307
critical
9.8
2021-08-16 CVE-2020-18699 Cross-site Scripting vulnerability in Talelin Lin-Cms-Flask 0.1.1
Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'.
network
low complexity
talelin CWE-79
6.1
2021-08-16 CVE-2020-18701 Incorrect Authorization vulnerability in Talelin Lin-Cms-Flask 0.1.1
Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.
network
low complexity
talelin CWE-863
critical
9.8