Filtered by vendor Alldata
Subscriptions
Filtered by product Alldata
Subscriptions
Total
5 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-29434 | 1 Alldata | 1 Alldata | 2025-04-30 | 8.3 High |
An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file. | ||||
CVE-2024-29432 | 1 Alldata | 1 Alldata | 2025-04-30 | 9.8 Critical |
Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/datas. | ||||
CVE-2024-27602 | 1 Alldata | 1 Alldata | 2025-04-30 | 9.1 Critical |
Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v2/api-docs module. | ||||
CVE-2024-27605 | 1 Alldata | 1 Alldata | 2025-03-28 | 7.5 High |
Alldata V0.4.6 is vulnerable to Insecure Permissions. Using users (test) can query information about the users in the system. | ||||
CVE-2024-27604 | 1 Alldata | 1 Alldata | 2025-03-27 | 9.8 Critical |
Alldata V0.4.6 is vulnerable to Command execution vulnerability. System commands can be deserialized. |
Page 1 of 1.