Filtered by vendor Sonicjs
                        
                        Subscribe
                        
                        
                    
                    
                
                    Total
                    2 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 | 
|---|---|---|---|---|---|
| CVE-2023-33690 | 1 Sonicjs | 1 Sonicjs | 2024-11-21 | N/A | 6.5 MEDIUM | 
| SonicJS up to v0.7.0 allows attackers to execute an authenticated path traversal when an attacker injects special characters into the filename of a backup CMS. | |||||
| CVE-2022-42002 | 1 Sonicjs | 1 Sonicjs | 2024-11-21 | N/A | 9.1 CRITICAL | 
| SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate and fileUpdate. Both of these mutations can be called without any authentication to overwrite any files on a SonicJS application, leading to Arbitrary File Write and Delete. | |||||
