Skip to main content

Vendor/product archive

kallithea-scm / kallithea CVEs

Beta · best-effort

5 CVEs tagged to kallithea-scm / kallithea0 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2015-1864

Published Sep 19, 2017

Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1)…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3691

Published Apr 24, 2017

Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5285

Published Oct 29, 2015

CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the came_from paramet…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1