Showing 2 vulnerabilities on this page for github.com/tiagorlampert/CHAOS

Signals CISA KEV Ransomware Nuclei
Go vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

tiagorlampert CHAOS vulnerable to arbitrary code execution

An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` string without any sanitization or filtering.

CWE-78May 7, 2024
CVSS9.8v3.1EPSS1.37%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

tiagorlampert CHAOS vulnerable to Cross Site Scripting

Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via the sendCommandHandler function in the handler.go component.

CWE-79Apr 12, 20241 related artifact
CVSS4.8v3.1EPSS8.04%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX