Vulnerabilities (CVE)

Filtered by vendor Rangerstudio Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-13983 1 Rangerstudio 1 Directus 7 Api 2019-07-22 5.0 MEDIUM 9.8 CRITICAL
Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php.
CVE-2018-10723 1 Rangerstudio 1 Directus 2018-06-12 7.5 HIGH 9.8 CRITICAL
Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.