Vulnerabilities (CVE)

Filtered by vendor Rapid7 Subscribe
Filtered by product Velociraptor
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-5950 1 Rapid7 1 Velociraptor 2023-11-14 N/A 6.1 MEDIUM
Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerability allows attackers to inject JS into the error path, potentially leading to unauthorized execution of scripts within a user's web browser. This vulnerability is fixed in version 0.7.0-04 and a patch is available to download. Patches are also available for version 0.6.9 (0.6.9-1).
CVE-2021-3619 1 Rapid7 1 Velociraptor 2021-08-02 3.5 LOW 4.8 MEDIUM
Rapid7 Velociraptor 0.5.9 and prior is vulnerable to a post-authentication persistent cross-site scripting (XSS) issue, where an authenticated user could abuse MIME filetype sniffing to embed executable code on a malicious upload. This issue was fixed in version 0.6.0. Note that login rights to Velociraptor is nearly always reserved for trusted and verified users with IT security backgrounds.