Gitee Exploits

260 exploits tracked across all sources.

Sort: Activity Stars
CVE-2023-30331 GITEE CRITICAL java
beetl <3.15.0 - Code Injection
An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.
by xiandafu
643 stars
CVSS 9.8
CVE-2024-22533 GITEE CRITICAL java
Before Beetl <3.15.12 - Code Injection
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be bypassed, leading to arbitrary code execution.
by xiandafu
643 stars
CVSS 9.8
CVE-2023-1937 GITEE MEDIUM java
zhenfeng13 My-Blog - CSRF
A vulnerability, which was classified as problematic, was found in zhenfeng13 My-Blog. Affected is an unknown function of the file /admin/configurations/userInfo. The manipulation of the argument yourAvatar/yourName/yourEmail leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of this vulnerability is VDB-225264.
by zhenfeng13
631 stars
CVSS 4.3
CVE-2023-27093 GITEE MEDIUM java
My-Blog - XSS
Cross Site Scripting vulnerability found in My-Blog allows attackers to cause a denial of service via the Post function.
by zhenfeng13
631 stars
CVSS 6.1
CVE-2023-7226 GITEE MEDIUM java
meetyoucrop big-whale 1.1 - Improper Ownership Management
A vulnerability was found in meetyoucrop big-whale 1.1 and classified as critical. Affected by this issue is some unknown functionality of the file /auth/user/all.api of the component Admin Module. The manipulation of the argument id leads to improper ownership management. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250232.
by progr1mmer
596 stars
CVSS 6.3
CVE-2022-4347 GITEE LOW java
xiandafu beetl-bbs - XSS
A vulnerability was found in xiandafu beetl-bbs. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file WebUtils.java. The manipulation of the argument user leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215107.
by xiandafu
546 stars
CVSS 3.5
CVE-2023-50449 GITEE HIGH java
Jfinalcms - Path Traversal
JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey parameter.
by heyewei
541 stars
CVSS 7.5
CVE-2024-24029 GITEE CRITICAL java
Jfinalcms - SQL Injection
JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.
by heyewei
541 stars
CVSS 9.8
CVE-2023-0287 GITEE LOW java
Ityouknow favorites-web - XSS
A vulnerability was found in ityouknow favorites-web. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Comment Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-218294 is the identifier assigned to this vulnerability.
by ityouknow
442 stars
CVSS 3.5
CVE-2023-1484 GITEE MEDIUM java
xzjie cms <1.0.3 - Unrestricted Upload
A vulnerability was found in xzjie cms up to 1.0.3 and classified as critical. This issue affects some unknown processing of the file /api/upload. The manipulation of the argument uploadFile leads to unrestricted upload. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-223367.
by xzjie
387 stars
CVSS 6.3
CVE-2023-1398 GITEE MEDIUM java
XiaoBingBy TeaCMS 2.0 - Path Traversal
A vulnerability classified as critical was found in XiaoBingBy TeaCMS 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/upload. The manipulation leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222985 was assigned to this vulnerability.
by xiaobingby
354 stars
CVSS 6.3
CVE-2023-1483 GITEE MEDIUM java
XiaoBingBy TeaCMS <2.0.2 - SQL Injection
A vulnerability has been found in XiaoBingBy TeaCMS up to 2.0.2 and classified as critical. This vulnerability affects unknown code of the file /admin/getallarticleinfo. The manipulation of the argument searchInfo leads to sql injection. The attack can be initiated remotely. VDB-223366 is the identifier assigned to this vulnerability.
by xiaobingby
354 stars
CVSS 6.3
CVE-2023-1616 GITEE LOW java
XiaoBingBy TeaCMS <=2.0.2 - XSS
A vulnerability was found in XiaoBingBy TeaCMS up to 2.0.2. It has been classified as problematic. Affected is an unknown function of the component Article Title Handler. The manipulation with the input <script>alert(document.cookie)</script> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223800.
by xiaobingby
354 stars
CVSS 3.5
CVE-2023-27090 GITEE MEDIUM java
TeaCMS - XSS
Cross Site Scripting vulnerability found in TeaCMS storage allows attacker to cause a leak of sensitive information via the article title parameter.
by xiaobingby
354 stars
CVSS 5.4
CVE-2023-27090 GITEE MEDIUM java
TeaCMS - XSS
Cross Site Scripting vulnerability found in TeaCMS storage allows attacker to cause a leak of sensitive information via the article title parameter.
by xiaobingby
354 stars
CVSS 5.4
CVE-2023-27091 GITEE HIGH java
TeaCMS 2.3.3 - Privilege Escalation
An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate privileges via the id and keywords parameter(s).
by xiaobingby
354 stars
CVSS 7.2
CVE-2023-27091 GITEE HIGH java
TeaCMS 2.3.3 - Privilege Escalation
An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate privileges via the id and keywords parameter(s).
by xiaobingby
354 stars
CVSS 7.2
CVE-2022-4400 GITEE LOW java
Fs-blog - XSS
A vulnerability was found in zbl1996 FS-Blog and classified as problematic. This issue affects some unknown processing of the component Title Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-215267.
by zbl1996
289 stars
CVSS 3.5
CVE-2023-39016 GITEE CRITICAL java
bboss-persistent <6.0.9 - Code Injection
bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument.
by bbossgroups
147 stars
CVSS 9.8
CVE-2022-42983 GITEE HIGH java
Anji-plus Aj-report - Authentication Bypass by Spoofing
anji-plus AJ-Report 0.9.8.6 allows remote attackers to bypass login authentication by spoofing JWT Tokens.
by Raod
72 stars
CVSS 8.8
CVE-2024-13022 GITEE MEDIUM java
Taisan Tarzan-cms 1.0.0 - Unrestricted Upload
A vulnerability, which was classified as critical, was found in taisan tarzan-cms 1.0.0. This affects the function UploadResponse of the file src/main/java/com/tarzan/cms/modules/admin/controller/common/UploadController.java of the component Article Management. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
by taisan
49 stars
CVSS 6.3
CVE-2022-4401 GITEE LOW java
Pallidlight Online Course Selection System - XSS
A vulnerability was found in pallidlight online-course-selection-system. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-215268.
by pallidlight
42 stars
CVSS 3.5
CVE-2018-20596 GITEE CRITICAL java
Jspxcms - SSRF
Jspxcms v9.0.0 allows SSRF.
by jspxcms
7 stars
CVSS 9.8
CVE-2022-23329 GITEE CRITICAL java
Ujcms Jspxcms - Unrestricted File Upload
A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.
by jspxcms
7 stars
CVSS 9.8
CVE-2022-28090 GITEE MEDIUM java
Ujcms Jspxcms - SSRF
Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=.
by jspxcms
7 stars
CVSS 6.5