OpenRefine是一款基于Java的开源工具。该产品主要用于加载数据、分析数据和清理数据等。 OpenRefine 3.8.3版本之前存在SQL注入漏洞,该漏洞源于在database扩展中,可以为SQLite集成设置enable_load_extension属性,使攻击者能够加载扩展DLL,从而在服务器上运行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenRefine | OpenRefine | >= 3.4-beta, < 3.8.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-47883 | 9.1 CRITICAL | Butterfly has path/URL confusion in resource handling leading to multiple weaknesses |
| CVE-2024-47878 | 8.1 HIGH | Reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt) |
| CVE-2024-47880 | 8.1 HIGH | OpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportR |
| CVE-2024-47879 | 7.6 HIGH | OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site |
| CVE-2024-49760 | 7.1 HIGH | OpenRefine has a path traversal in LoadLanguageCommand |
| CVE-2024-47882 | 5.9 MEDIUM | OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on impor |
No comments yet