Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2024-50344

Disclosure Date: October 30, 2024 (last updated October 31, 2024)
I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browser, only if they have a white-listed MIME type. Unfortunately, this logic is broken, thus allowing unsafe files containing Javascript to be executed with the application context. An attacker can exploit this vulnerability by uploading a supplementary file that contains a malicious code or script. This code will then be executed when the file is loaded in the browser. The vulnerability was fixed in version 5.11.2.
0
Attacker Value
Unknown

CVE-2024-40500

Disclosure Date: August 12, 2024 (last updated February 26, 2025)
Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in the import component.
Attacker Value
Unknown

CVE-2024-41943

Disclosure Date: July 30, 2024 (last updated February 26, 2025)
I, Librarian is an open-source version of a PDF managing SaaS. PDF notes are displayed on the Item Summary page without any form of validation or sanitation. An attacker can exploit this vulnerability by inserting a payload in the PDF notes that contains malicious code or script. This code will then be executed when the page is loaded in the browser. The vulnerability was fixed in version 5.11.1.
0
Attacker Value
Unknown

CVE-2023-3021

Disclosure Date: May 31, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository mkucej/i-librarian-free prior to 5.10.4.
Attacker Value
Unknown

CVE-2023-3020

Disclosure Date: May 31, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Reflected in GitHub repository mkucej/i-librarian-free prior to 5.10.4.
Attacker Value
Unknown

CVE-2022-47854

Disclosure Date: January 31, 2023 (last updated February 24, 2025)
i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php.
Attacker Value
Unknown

CVE-2019-11449

Disclosure Date: April 22, 2019 (last updated November 27, 2024)
I, Librarian 4.10 has XSS via the notes.php notes parameter.
0
Attacker Value
Unknown

CVE-2019-11428

Disclosure Date: April 22, 2019 (last updated November 27, 2024)
I, Librarian 4.10 has XSS via the export.php export_files parameter.
0
Attacker Value
Unknown

CVE-2019-11359

Disclosure Date: April 20, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in display.php in I, Librarian 4.10 allows remote attackers to inject arbitrary web script or HTML via the project parameter.
0
Attacker Value
Unknown

CVE-2018-1000139

Disclosure Date: March 23, 2018 (last updated November 26, 2024)
I, Librarian version 4.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in "id" parameter in stable.php that can result in an attacker using the XSS to send a malicious script to an unsuspecting user.
0