Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2024-29319

Disclosure Date: July 05, 2024 (last updated July 09, 2024)
Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and DNS requests to a server that the attacker controls.
Attacker Value
Unknown

CVE-2024-29318

Disclosure Date: July 05, 2024 (last updated July 09, 2024)
Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code.
Attacker Value
Unknown

CVE-2023-43838

Disclosure Date: October 04, 2023 (last updated October 09, 2023)
An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.