11.0.15
1 years ago
11 days ago
Known vulnerabilities in the @haxtheweb/haxcms-nodejs package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
@haxtheweb/haxcms-nodejs is a HAXcms nodejs backend Affected versions of this package are vulnerable to Improper Authorization in the API endpoints, which do not verify user permissions before performing operations. An attacker can gain unauthorized access to resources or perform actions beyond their intended privileges by sending crafted requests to the affected endpoints. How to fix Improper Authorization? Upgrade | <11.0.14 |
@haxtheweb/haxcms-nodejs is a HAXcms nodejs backend Affected versions of this package are vulnerable to Insecure Default Initialization of Resource due to insecure default settings that disable authentication and authorization checks. An attacker can gain unauthorized access to, modify, or delete all site information by sending unauthenticated requests to the application. This is only exploitable if the default configuration is used without enabling authentication. How to fix Insecure Default Initialization of Resource? Upgrade | <11.0.7 |
@haxtheweb/haxcms-nodejs is a HAXcms nodejs backend Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to the How to fix Cross-site Scripting (XSS)? Upgrade | <11.0.8 |
@haxtheweb/haxcms-nodejs is a HAXcms nodejs backend Affected versions of this package are vulnerable to Improper Input Validation via the How to fix Improper Input Validation? Upgrade | <11.0.9 |
@haxtheweb/haxcms-nodejs is a HAXcms nodejs backend Affected versions of this package are vulnerable to Use of Default Credentials via the Note: This is exploitable if the instance is deployed without changing the default credentials or secrets. How to fix Use of Default Credentials? Upgrade | <11.0.10 |
@haxtheweb/haxcms-nodejs is a HAXcms nodejs backend Affected versions of this package are vulnerable to Improper Restriction of Rendered UI Layers or Frames via the lack of appropriate headers to prevent loading within an iframe. An attacker can trick users into performing unintended actions by embedding sensitive pages such as the standalone login page or other critical functionality within an iframe on a malicious site. How to fix Improper Restriction of Rendered UI Layers or Frames? Upgrade | <11.0.13 |