Vulnerabilities (CVE)

Filtered by vendor Beego Subscribe
Filtered by product Beego
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-39391 1 Beego 1 Beego 2021-09-24 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in the admin panel in Beego v2.0.1 via the URI path in an HTTP request, which is activated by administrators viewing the "Request Statistics" page.
CVE-2019-16354 1 Beego 1 Beego 2021-07-21 1.9 LOW 4.7 MEDIUM
The File Session Manager in Beego 1.10.0 allows local users to read session files because there is a race condition involving file creation within a directory with weak permissions.
CVE-2019-16355 1 Beego 1 Beego 2019-09-17 2.1 LOW 5.5 MEDIUM
The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files.