Skip to main content

Vendor/product archive

ptc / vuforia_studio CVEs

Beta · best-effort

6 CVEs tagged to ptc / vuforia_studio0 Critical, 1 High, 3 Medium, 2 Low, 0 Unrated.

CVE-2023-31200

Published Jun 7, 2023

PTC Vuforia Studio does not require a token; this could allow an attacker with local access to perform a cross-site request forgery attack or a replay attack.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29502

Published Jun 7, 2023

Before importing a project into Vuforia, a user could modify the “resourceDirectory” attribute in the appConfig.json file to be a different path.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29168

Published Jun 7, 2023

The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-29152

Published Jun 7, 2023

By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27881

Published Jun 7, 2023

A user could use the “Upload Resource” functionality to upload files to any location on the disk.

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-24476

Published Jun 7, 2023

An attacker with local access to the machine could record the traffic, which could allow them to resend requests without the server authenticating that the user or session are v…

CVSS 1.8 · Low
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1