Skip to main content

Vendor archive

luckyframe CVEs

Beta · best-effort

5 CVEs tagged to vendor luckyframe3 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2024-35081

Published May 23, 2024

LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in the fileDownload method.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-33118

Published May 6, 2024

LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.common.CommonController.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-24221

Published Feb 17, 2023

LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-24220

Published Feb 17, 2023

LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-24219

Published Feb 17, 2023

LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1