Loading HuntDB...

Vulnerabilities

CVE-2023-0109

CRITICAL

A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is accessed, the malicious script is executed. This can lead to the theft of sensitive information, such as login credentials, from users visiting the affected website. The issue has been fixed in version 0.10.0.

Published Nov 15, 2024

CVE-2024-41659

HIGH

memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. This vulnerability is fixed in 0.21.0.

Published Aug 20, 2024

CVE-2024-29029

MEDIUM

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the response of the current server request, causing a reflected XSS vulnerability. Version 0.22.0 of memos removes the vulnerable file.

Published Apr 19, 2024

CVE-2024-29028

MEDIUM

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vulnerability is fixed in 0.16.1.

Published Apr 19, 2024

CVE-2024-29030

MEDIUM

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file.

Published Apr 19, 2024

CVE-2023-5036

HIGH

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.

Published Sep 18, 2023

CVE-2023-4697

HIGH

Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.

Published Sep 01, 2023

CVE-2023-4698

HIGH

Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.

Published Sep 01, 2023

CVE-2023-4696

CRITICAL

Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.

Published Sep 01, 2023

CVE-2023-0108

HIGH

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Published Jan 07, 2023

CVE-2023-0111

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Published Jan 07, 2023

CVE-2023-0110

HIGH

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Published Jan 07, 2023

CVE-2023-0112

HIGH

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Published Jan 07, 2023

CVE-2023-0106

CRITICAL

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Published Jan 07, 2023

CVE-2023-0107

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Published Jan 07, 2023

CVE-2022-4866

CRITICAL

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 31, 2022

CVE-2022-4865

HIGH

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 31, 2022

CVE-2022-4863

HIGH

Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 30, 2022

CVE-2022-4844

MEDIUM

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 29, 2022

CVE-2022-4841

HIGH

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 29, 2022

CVE-2022-4846

MEDIUM

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 29, 2022

CVE-2022-4851

CRITICAL

Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 29, 2022

CVE-2022-4845

MEDIUM

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 29, 2022

CVE-2022-4849

HIGH

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 29, 2022

CVE-2022-4840

HIGH

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 29, 2022

CVE-2022-4848

HIGH

Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 29, 2022

CVE-2022-4847

HIGH

Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 29, 2022

CVE-2022-4850

MEDIUM

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 29, 2022

CVE-2022-4839

HIGH

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 29, 2022

CVE-2022-4798

HIGH

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4800

HIGH

Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4802

CRITICAL

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4803

HIGH

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4809

HIGH

Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4797

CRITICAL

Improper Restriction of Excessive Authentication Attempts in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4799

HIGH

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4807

HIGH

Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4814

HIGH

Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4813

HIGH

Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4805

HIGH

Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4810

MEDIUM

Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4812

HIGH

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4804

HIGH

Improper Authorization in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4811

HIGH

Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.

Published Dec 28, 2022

CVE-2022-4808

MEDIUM

Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4801

HIGH

Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4806

HIGH

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4796

HIGH

Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 28, 2022

CVE-2022-4767

HIGH

Denial of Service in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 27, 2022

CVE-2022-4734

HIGH

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository usememos/memos prior to 0.9.1.

Published Dec 25, 2022