papermerge-core@2.0.0rc13 vulnerabilities

Open source document management system for digital archives

  • latest version

    2.1.5

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    1 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the papermerge-core package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    papermerge-core is an Open source document management system designed for scanned documents

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in case of form.save(commit=False). An attacker could gain access to sensitive data.

    How to fix Cross-site Scripting (XSS)?

    Upgrade papermerge-core to version 2.0.0rc35 or higher.

    [,2.0.0rc35)
    • H
    Authorization Bypass Through User-Controlled Key

    papermerge-core is an Open source document management system designed for scanned documents

    Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via document-versions/uuid:pk/download/ API by allowing any user to download any file.

    How to fix Authorization Bypass Through User-Controlled Key?

    Upgrade papermerge-core to version 2.1.0b7 or higher.

    [,2.1.0b7)