📦 Konga

by Pantsel

🔍 What is Konga?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-39846

CRITICAL CVSS 9.8 Aug 16, 2023

This vulnerability allows attackers to bypass authentication in Konga v0.14.9 by crafting malicious JWT tokens. Attackers can gain unauthorized administrative access to the Konga management interface....

CVE-2024-34243

MEDIUM CVSS 5.4 May 14, 2024

Konga v0.14.9 is vulnerable to Cross-Site Scripting (XSS) via the username parameter, allowing attackers to inject malicious scripts that execute in users' browsers. This affects administrators and us...