Skip to main content

Vendor archive

rangerstudio CVEs

Beta · best-effort

17 CVEs tagged to vendor rangerstudio2 Critical, 8 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2023-27474

Published Mar 6, 2023

Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed reset URL are vulnerable to an HTML injection attack through…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23080

Published Jun 22, 2022

In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perfo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24814

Published Apr 4, 2022

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized JavaScript (JS) can be executed by inserting an iframe into t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22117

Published Jan 10, 2022

In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cross-Site Scripting vulnerabilit…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22116

Published Jan 10, 2022

In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file upload in media upload functionality. A low privil…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29641

Published Apr 7, 2021

Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include the ability to upload a .php file to the main upload di…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27583

Published Feb 23, 2021

In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature. NOTE: This vulnerability only affects product…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26595

Published Feb 23, 2021

In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by vi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26594

Published Feb 23, 2021

In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects p…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26593

Published Feb 23, 2021

In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they get in response a lot of information about the user (such as…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13984

Published Jul 19, 2019

Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a direct link to each uploaded file, accessible by unauthenti…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13983

Published Jul 19, 2019

Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-13982

Published Jul 19, 2019

interfaces/markdown/input.vue in Directus 7 Application before 7.7.0 does not sanitize Markdown text before rendering a preview.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13981

Published Jul 19, 2019

In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory. This is related to a configura…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13980

Published Jul 19, 2019

In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals remote code execution with nginx.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13979

Published Jul 19, 2019

In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10723

Published May 5, 2018

Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1