DSpace是DuraSpace社区的一个开源的交钥匙存储库应用程序。 DSpace 4.0 到 6.3版本存在路径遍历漏洞,该漏洞源于意 SAF(简单存档格式)包可能会导致在 Tomcat/DSpace 用户可以在服务器上写入的任何位置创建文件/目录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/shoucheng3/DSpace__DSpace_CVE-2022-31195_5-10 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-31194 | 8.2 HIGH | Path traversal vulnerabilities in DSpace JSPUI submission upload |
| CVE-2022-31191 | 7.1 HIGH | Cross Site Scripting possible in DSpace JSPUI spellcheck and autocomplete tools |
| CVE-2022-31192 | 7.1 HIGH | Cross Site Scripting possible in DSpace JSPUI "Request a Copy" feature |
| CVE-2022-31193 | 7.1 HIGH | URL Redirection to Untrusted Site in Dspace JSPUI |
| CVE-2022-31189 | 5.3 MEDIUM | "Internal System Error" page in DSpace JSPUI prints exceptions and stack traces without sa |
| CVE-2022-31190 | 5.3 MEDIUM | Metadata of withdrawn Items is exposed to anonymous users in DSpace XMLUI |
No comments yet