baidu Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with baidu products.
Products
- UEditor2 vulnerabilities
- Baidu Antivirus1 vulnerability
- baidu_openrasp1 vulnerability
- openrasp1 vulnerability
- soba_search_bar1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Improper Privilege ManagementAn issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your Own Vulnerable Driver) attack. CWE-269Feb 11, 2025 | CVSS3.8v3.1 | EPSS0.472% | PoCs1 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX | |
CVE-2024-7343MEDIUM | Baidu UEditor cross site scriptingA vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor142/php/controller.php?action=catchimage. The manipulation of the argument source[] leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273274 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respon… CWE-79Aug 1, 2024 | CVSS5.3v4.0 | EPSS0.453% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-7342MEDIUM | Baidu UEditor unrestricted uploadA vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/controller.php?action=uploadfile&encode=utf-8. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273273 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did… CWE-434Aug 1, 2024 | CVSS5.3v4.0 | EPSS0.453% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29183MEDIUM | OpenRASP vulnerable to a reflected Cross-Site Scripting (XSS) attack in /loginOpenRASP is a RASP solution that directly integrates its protection engine into the application server by instrumentation. There exists a reflected XSS in the /login page due to a reflection of the redirect parameter. This allows an attacker to execute arbitrary javascript with the permissions of a user after the user logins with their account. CWE-79Apr 19, 2024 | CVSS6.1v3.1 | EPSS0.403% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Baidu Soba Search Bar 'BaiduBar.dll' VulnerabilityA certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request containing "a link to download and a file to execute," possibly involving remote file inclusion. Jul 31, 2007 | CVSS9.3v2.0 | EPSS7.32% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |