com.xnx3.wangmarket:wangmarket@5.3 vulnerabilities

  • latest version

    5.6.17

  • first published

    4 years ago

  • latest version published

    2 years ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the com.xnx3.wangmarket:wangmarket package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Request Forgery (CSRF)

    Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) via the /agency/AgencyUserController.java component. An attacker can manipulate the state of the application on behalf of users by sending a crafted request that the end user's browser processes.

    How to fix Cross-site Request Forgery (CSRF)?

    There is no fixed version for com.xnx3.wangmarket:wangmarket.

    [0,)
    • M
    Cross-site Scripting (XSS)

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the Role Management Page. An attacker can inject arbitrary code and execute it on the server by manipulating the affected component. This is only exploitable if the attacker has high-level privileges to access the Role Management Page.

    How to fix Cross-site Scripting (XSS)?

    There is no fixed version for com.xnx3.wangmarket:wangmarket.

    [0,)
    • H
    SQL Injection

    Affected versions of this package are vulnerable to SQL Injection via the TableName parameter.

    How to fix SQL Injection?

    There is no fixed version for com.xnx3.wangmarket:wangmarket.

    [0,)