Ligeo Archives是法国Ligeo Archives社区的一款档案管理软件。 Ligeo Archives 的Ligeo Basics 存在安全漏洞,该漏洞源于Ligeo Basics受到服务器端请求伪造 (SSRF) 的攻击。该漏洞允许攻击者通过下载功能读取任何文档。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacker to read any documents via the download features. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-46107.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-0748 | 9.8 CRITICAL | Arbitrary Code Execution |
| CVE-2022-25354 | 8.6 HIGH | Prototype Pollution |
| CVE-2022-25352 | 7.5 HIGH | Prototype Pollution |
| CVE-2022-0749 | 7.4 HIGH | Deserialization of Untrusted Data |
| CVE-2022-25760 | 7.1 HIGH | Arbitrary Code Injection |
| CVE-2021-23632 | 6.6 MEDIUM | Remote Code Execution (RCE) |
| CVE-2021-23771 | 6.5 MEDIUM | Sandbox Bypass |
| CVE-2021-23556 | 6.4 MEDIUM | Exposed Dangerous Method or Function |
| CVE-2022-25296 | 6.3 MEDIUM | Prototype Pollution |
| CVE-2022-21221 | 5.9 MEDIUM | Directory Traversal |
| CVE-2022-26501 | Veeam Backup&Replication 访问控制错误漏洞 | |
| CVE-2021-45040 | Spatie Laravel Media Library Pro 代码问题漏洞 | |
| CVE-2022-25364 | Gradle 安全漏洞 | |
| CVE-2022-26503 | Veeam Agent for Windows 代码问题漏洞 | |
| CVE-2020-15591 | F*EX 代码注入漏洞 | |
| CVE-2021-44908 | Sails.js 注入漏洞 | |
| CVE-2022-26526 | Anaconda Anaconda3和Miniconda3 代码问题漏洞 | |
| CVE-2022-26504 | Veeam Backup&Replication 授权问题漏洞 | |
| CVE-2022-26500 | Veeam Backup&Replication 路径遍历漏洞 | |
| CVE-2022-24302 | Paramiko 竞争条件问题漏洞 |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet