Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2024-3928

Disclosure Date: April 18, 2024 (last updated April 18, 2024)
A vulnerability was found in Dromara open-capacity-platform 2.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /actuator/heapdump of the component auth-server. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261367.
0
Attacker Value
Unknown

CVE-2023-44794

Disclosure Date: October 25, 2023 (last updated November 01, 2023)
An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.
Attacker Value
Unknown

CVE-2023-43961

Disclosure Date: October 25, 2023 (last updated November 02, 2023)
An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Attacker Value
Unknown

CVE-2023-31581

Disclosure Date: October 25, 2023 (last updated November 01, 2023)
Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.
Attacker Value
Unknown

CVE-2023-3276

Disclosure Date: June 15, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the function readBySax of the file XmlUtil.java of the component XML Parsing Module. The manipulation leads to xml external entity reference. The exploit has been disclosed to the public and may be used. VDB-231626 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.