Known Vulnerabilities for Freetakserver-ui by Freetakserver-ui Project
Listed below are 6 of the newest known vulnerabilities associated with "Freetakserver-ui" by "Freetakserver-ui Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-25512 json | FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys. | 7.5 - HIGH | 2022-03-11 | 2022-03-22 |
| CVE-2022-25511 json | An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbit... | 6.5 - MEDIUM | 2022-03-11 | 2022-03-22 |
| CVE-2022-25510 json | FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authenti... | 8.8 - HIGH | 2022-03-11 | 2022-03-22 |
| CVE-2022-25508 json | An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to c... | 7.5 - HIGH | 2022-03-11 | 2023-08-08 |
| CVE-2022-25507 json | FreeTAKServer-UI v1.9.8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Callsign paramete... | 5.4 - MEDIUM | 2022-03-11 | 2022-03-22 |
| CVE-2022-25506 json | FreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser. | 6.5 - MEDIUM | 2022-03-11 | 2022-03-22 |