DSpace是DuraSpace社区的一个开源的交钥匙存储库应用程序。 DSpace 6.4之前版本存在信息泄露漏洞,该漏洞源于dspace-xmlui中已撤销项目的元数据会被 XMLUImets.xml对象公开。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-31194 | 8.2 HIGH | Path traversal vulnerabilities in DSpace JSPUI submission upload |
| CVE-2022-31195 | 7.2 HIGH | Path traversal vulnerability in Simple Archive Format package import in DSpace |
| CVE-2022-31191 | 7.1 HIGH | Cross Site Scripting possible in DSpace JSPUI spellcheck and autocomplete tools |
| CVE-2022-31192 | 7.1 HIGH | Cross Site Scripting possible in DSpace JSPUI "Request a Copy" feature |
| CVE-2022-31193 | 7.1 HIGH | URL Redirection to Untrusted Site in Dspace JSPUI |
| CVE-2022-31189 | 5.3 MEDIUM | "Internal System Error" page in DSpace JSPUI prints exceptions and stack traces without sa |
No comments yet