📦 Luckyframeweb

by Luckyframe

🔍 What is Luckyframeweb?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-24221

CRITICAL CVSS 9.8 Feb 17, 2023

LuckyframeWEB v3.5 contains a SQL injection vulnerability in the dataScope parameter at /system/DeptMapper.xml that allows attackers to execute arbitrary SQL commands. This affects all deployments of ...

CVE-2023-24219

CRITICAL CVSS 9.8 Feb 17, 2023

LuckyframeWEB v3.5 contains a SQL injection vulnerability in the dataScope parameter at /system/UserMapper.xml that allows attackers to execute arbitrary SQL commands. This affects all deployments of ...

CVE-2024-33118

HIGH CVSS 7.5 May 6, 2024

LuckyFrameWeb v3.5.2 contains an arbitrary file read vulnerability in the fileDownload method of CommonController. This allows attackers to read sensitive files from the server filesystem without auth...