Showing 3 vulnerabilities on this page for LabKey Server Community Edition

Signals CISA KEV Ransomware Nuclei
Tenable vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker to unmount any drive on the system leading to denial of service.

CWE-77CWE-78Jan 30, 2019
CVSS4.9v3.1EPSS1.74%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

LabKey Server Community Edition <18.3.0 - Open Redirect

An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary web sites.

CWE-601Jan 30, 20191 related artifact
CVSS6.1v3.1EPSS4.83%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

LabKey Server Community Edition <18.3.0 - Cross-Site Scripting

Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remote attacker to inject arbitrary javascript via the onerror parameter in the /__r2/query endpoints.

CWE-79Jan 30, 20191 related artifact
CVSS6.1v3.1EPSS3.81%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX