Vulnerabilities
CVE-2023-0109
CRITICALA stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is accessed, the malicious script is executed. This can lead to the theft of sensitive information, such as login credentials, from users visiting the affected website. The issue has been fixed in version 0.10.0.
CVE-2024-41659
HIGHmemos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. This vulnerability is fixed in 0.21.0.
CVE-2024-29029
MEDIUMmemos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the response of the current server request, causing a reflected XSS vulnerability. Version 0.22.0 of memos removes the vulnerable file.
CVE-2024-29028
MEDIUMmemos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vulnerability is fixed in 0.16.1.
CVE-2024-29030
MEDIUMmemos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file.
CVE-2023-5036
HIGHCross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.
CVE-2023-4697
HIGHImproper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.
CVE-2023-4698
HIGHImproper Input Validation in GitHub repository usememos/memos prior to 0.13.2.
CVE-2023-4696
CRITICALImproper Access Control in GitHub repository usememos/memos prior to 0.13.2.
CVE-2023-0108
HIGHCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
CVE-2023-0111
MEDIUMCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
CVE-2023-0110
HIGHCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
CVE-2023-0112
HIGHCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
CVE-2023-0106
CRITICALCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
CVE-2023-0107
MEDIUMCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
CVE-2022-4866
CRITICALCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4865
HIGHCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4863
HIGHImproper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4844
MEDIUMCross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4841
HIGHCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4846
MEDIUMCross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4851
CRITICALImproper Handling of Values in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4845
MEDIUMCross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4849
HIGHCross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4840
HIGHCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4848
HIGHImproper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4847
HIGHIncorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4850
MEDIUMCross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4839
HIGHCross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4798
HIGHAuthorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4800
HIGHImproper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4802
CRITICALAuthorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4803
HIGHAuthorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4809
HIGHImproper Access Control in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4797
CRITICALImproper Restriction of Excessive Authentication Attempts in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4799
HIGHAuthorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4807
HIGHImproper Access Control in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4814
HIGHImproper Access Control in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4813
HIGHInsufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4805
HIGHIncorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4810
MEDIUMImproper Access Control in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4812
HIGHAuthorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4804
HIGHImproper Authorization in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4811
HIGHAuthorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.
CVE-2022-4808
MEDIUMImproper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4801
HIGHInsufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4806
HIGHAuthorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4796
HIGHIncorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4767
HIGHDenial of Service in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4734
HIGHImproper Removal of Sensitive Information Before Storage or Transfer in GitHub repository usememos/memos prior to 0.9.1.
Showing 1 to 50 of 62 vulnerabilities