Vulnerabilities > Tduckcloud
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-11 | CVE-2024-8692 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tduckcloud Tduckpro A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. | 9.8 |
2024-01-13 | CVE-2023-51805 | SQL Injection vulnerability in Tduckcloud Tduck-Platform 4.0 SQL Injection vulnerability in TDuckCLoud tduck-platform v.4.0 allows a remote attacker to obtain sensitive information via the getFormKey parameter in the search function of FormDataMysqlService.java file. | 6.5 |
2023-07-19 | CVE-2023-37733 | Cross-site Scripting vulnerability in Tduckcloud Tduck-Platform 4.0 An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted HTML file. | 6.1 |