Autore: Angelo Barbosa

CVE-2023-49734 | Apache Superset up to 2.1.1/3.0.1 Chart authorization

A vulnerability, which was classified as problematic, was found in Apache Superset up to 2.1.1/3.0.1. Affected is an unknown function of the component Chart Handler. The manipulation leads to incorrect authorization. This vulnerability is traded as CVE-2023-49734. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-49736 | Apache Superset up to 2.1.1/3.0.1 JINJA Macro sql injection

A vulnerability, which was classified as critical, has been found in Apache Superset up to 2.1.1/3.0.1. This issue affects some unknown processing of the component JINJA Macro Handler. The manipulation leads to sql injection. The identification of this vulnerability is CVE-2023-49736. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-46104 | Apache Superset up to 2.1.2/3.0.1 ZIP File resource consumption

A vulnerability classified as critical was found in Apache Superset up to 2.1.2/3.0.1. This vulnerability affects unknown code of the component ZIP File Handler. The manipulation leads to resource consumption. This vulnerability was named CVE-2023-46104. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-49489 | kalcaddle KodeExplorer 4.51 config/i18n/en/main.php APP_HOST cross site scripting

A vulnerability was found in kalcaddle KodeExplorer 4.51. It has been rated as problematic. Affected by this issue is some unknown functionality of the file config/i18n/en/main.php. The manipulation of the argument APP_HOST leads to cross site scripting. This vulnerability is handled as CVE-2023-49489. The attack may be launched remotely. There is no exploit...

Per saperne di più