DSpace是DuraSpace社区的一个开源的交钥匙存储库应用程序。 DSpace 4.0 到 6.3版本存在路径遍历漏洞,该漏洞源于SubmissionController 和 FileUploadRequest 中的 JSPUI允许攻击者通过在提交期间修改一些请求参数,在服务器上任何位置创建 Tomcat/DSpace 用户可写的文件或目录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/shoucheng3/DSpace__DSpace_CVE-2022-31194_5-10 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-31195 | 7.2 HIGH | Path traversal vulnerability in Simple Archive Format package import in DSpace |
| CVE-2022-31191 | 7.1 HIGH | Cross Site Scripting possible in DSpace JSPUI spellcheck and autocomplete tools |
| CVE-2022-31192 | 7.1 HIGH | Cross Site Scripting possible in DSpace JSPUI "Request a Copy" feature |
| CVE-2022-31193 | 7.1 HIGH | URL Redirection to Untrusted Site in Dspace JSPUI |
| CVE-2022-31189 | 5.3 MEDIUM | "Internal System Error" page in DSpace JSPUI prints exceptions and stack traces without sa |
| CVE-2022-31190 | 5.3 MEDIUM | Metadata of withdrawn Items is exposed to anonymous users in DSpace XMLUI |
No comments yet