Known Vulnerabilities for products from Freetakserver-ui Project
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Freetakserver-ui Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-25512 json | FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys. | 7.5 - HIGH | 2022-03-11 | 2022-03-22 |
| CVE-2022-25511 json | An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbit... | 6.5 - MEDIUM | 2022-03-11 | 2022-03-22 |
| CVE-2022-25510 json | FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authenti... | 8.8 - HIGH | 2022-03-11 | 2022-03-22 |
| CVE-2022-25508 json | An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to c... | 7.5 - HIGH | 2022-03-11 | 2023-08-08 |
| CVE-2022-25507 json | FreeTAKServer-UI v1.9.8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Callsign paramete... | 5.4 - MEDIUM | 2022-03-11 | 2022-03-22 |
| CVE-2022-25506 json | FreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser. | 6.5 - MEDIUM | 2022-03-11 | 2022-03-22 |