Known Vulnerabilities for products from Rangerstudio
Listed below are 17 of the newest known vulnerabilities associated with the vendor "Rangerstudio".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-27474 json | Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed reset U... | 5.4 - MEDIUM | 2023-03-06 | 2023-03-13 |
| CVE-2022-24814 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2022-04-04 | 2022-04-12 |
| CVE-2022-23080 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5 - MEDIUM | 2022-06-22 | 2023-11-07 |
| CVE-2022-22117 json | In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functiona... | 5.4 - MEDIUM | 2022-01-10 | 2022-01-14 |
| CVE-2022-22116 json | In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG f... | 5.4 - MEDIUM | 2022-01-10 | 2022-01-14 |
| CVE-2021-29641 json | Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include t... | 8.8 - HIGH | 2021-04-07 | 2021-04-13 |
| CVE-2021-27583 json | ** UNSUPPORTED WHEN ASSIGNED ** In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the data... | 5.3 - MEDIUM | 2021-02-23 | 2023-11-07 |
| CVE-2021-26595 json | ** UNSUPPORTED WHEN ASSIGNED ** In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the versio... | 5.3 - MEDIUM | 2021-02-23 | 2023-11-07 |
| CVE-2021-26594 json | ** UNSUPPORTED WHEN ASSIGNED ** In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATC... | 8.8 - HIGH | 2021-02-23 | 2023-11-07 |
| CVE-2021-26593 json | ** UNSUPPORTED WHEN ASSIGNED ** In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/... | 7.5 - HIGH | 2021-02-23 | 2023-11-07 |
| CVE-2019-13984 json | Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a direc... | 8.8 - HIGH | 2019-07-19 | 2019-07-22 |
| CVE-2019-13983 json | Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/... | 9.8 - CRITICAL | 2019-07-19 | 2019-07-22 |
| CVE-2019-13982 json | interfaces/markdown/input.vue in Directus 7 Application before 7.7.0 does not sanitize Markdown text before rendering a previ... | 5.3 - MEDIUM | 2019-07-19 | 2021-07-21 |
| CVE-2019-13981 json | In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/... | 5.3 - MEDIUM | 2019-07-19 | 2020-08-24 |
| CVE-2019-13980 json | In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploa... | 8.8 - HIGH | 2019-07-19 | 2019-07-22 |
| CVE-2019-13979 json | In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution. | 8.8 - HIGH | 2019-07-19 | 2019-07-22 |
| CVE-2018-10723 json | Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql. | 9.8 - CRITICAL | 2018-05-05 | 2018-06-12 |
Known software with vulnerabilities from Rangerstudio
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Rangerstudio | Directus | 6.0.5 |
| Application | Rangerstudio | Directus 7 | 7.0.0 |
| Application | Rangerstudio | Directus 7 Api | 2.0.0 |