Vulnerabilities (CVE)

Filtered by vendor Europeana Subscribe
Filtered by product Repox
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6719 1 Europeana 1 Repox 2023-12-18 N/A 6.1 MEDIUM
An XSS vulnerability has been detected in Repox, which allows an attacker to compromise interactions between a user and the vulnerable application, and can be exploited by a third party by sending a specially crafted JavaScript payload to a user, and thus gain full control of their session.
CVE-2023-6720 1 Europeana 1 Repox 2023-12-18 N/A 5.4 MEDIUM
An XSS vulnerability stored in Repox has been identified, which allows a local attacker to store a specially crafted JavaScript payload on the server, due to the lack of proper sanitisation of field elements, allowing the attacker to trigger the malicious payload when the application loads.