2.1

CVSS4.0

CVE-2024-47867 - Lack of integrity check on the downloaded FRP client in Gradio

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP client, which could potentially allow attackers to introduce malicious code. If an attacker gains access to the remote URL from which the FRP client is d…

📅 Published: Oct. 10, 2024, 10:19 p.m. 🔄 Last Modified: Nov. 15, 2024, 4:44 p.m.

6.3

CVSS4.0

CVE-2024-47868 - Several components’ post-process steps may allow arbitrary file leaks in Gradio

Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio components, which allows arbitrary file leaks through the post-processing step. Attackers can exploit these components by crafting requests that bypass expect…

📅 Published: Oct. 10, 2024, 10:18 p.m. 🔄 Last Modified: Oct. 17, 2024, 5:04 p.m.

2.3

CVSS4.0

CVE-2024-47869 - Non-constant-time comparison when comparing hashes in Gradio

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **timing attack** in the way Gradio compares hashes for the `analytics_dashboard` function. Since the comparison is not done in constant time, an attacker could exploit this by measuring the respon…

📅 Published: Oct. 10, 2024, 10:16 p.m. 🔄 Last Modified: Oct. 17, 2024, 4:59 p.m.

7.1

CVSS4.0

CVE-2024-47870 - Race condition in update_root_in_config may redirect user traffic in Gradio

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition** in the `update_root_in_config` function, allowing an attacker to modify the `root` URL used by the Gradio frontend to communicate with the backend. By exploiting this flaw, an at…

📅 Published: Oct. 10, 2024, 10:15 p.m. 🔄 Last Modified: Oct. 17, 2024, 4:57 p.m.

8.2

CVSS4.0

CVE-2024-47871 - Insecure communication between the FRP client and server in Gradio

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communication** between the FRP (Fast Reverse Proxy) client and server when Gradio's `share=True` option is used. HTTPS is not enforced on the connection, allowing attackers to intercept a…

📅 Published: Oct. 10, 2024, 10:14 p.m. 🔄 Last Modified: Oct. 17, 2024, 5:11 p.m.

6.9

CVSS4.0

CVE-2024-47872 - Cross-site Scripting on Gradio server via upload of HTML files, JS files, or SVG files

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **Cross-Site Scripting (XSS)** on any Gradio server that allows file uploads. Authenticated users can upload files such as HTML, JavaScript, or SVG files containing malicious scripts. When other user…

📅 Published: Oct. 10, 2024, 10:12 p.m. 🔄 Last Modified: Oct. 17, 2024, 4:54 p.m.

5.1

CVSS4.0

CVE-2024-9816 - Codezips Tourist Management System change-image.php unrestricted upload

A vulnerability was found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack may be launched remotely. …

📅 Published: Oct. 10, 2024, 10 p.m. 🔄 Last Modified: Oct. 17, 2024, 2:53 p.m.

6.9

CVSS4.0

CVE-2024-47084 - CORS origin validation is not performed when the request has a cookie in Gradio

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin validation**, where the Gradio server fails to validate the request origin when a cookie is present. This allows an attacker’s website to make unauthorized requests to a local Grad…

📅 Published: Oct. 10, 2024, 9:53 p.m. 🔄 Last Modified: Oct. 17, 2024, 4:30 p.m.

2.3

CVSS4.0

CVE-2024-47164 - The `is_in_or_equal` function may be bypassed in Gradio

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of directory traversal checks** within the `is_in_or_equal` function. This function, intended to check if a file resides within a given directory, can be bypassed with certain payloads…

📅 Published: Oct. 10, 2024, 9:52 p.m. 🔄 Last Modified: Oct. 17, 2024, 4:40 p.m.

6.9

CVSS4.0

CVE-2024-47165 - CORS origin validation accepts the null origin in Gradio

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin validation accepting a null origin**. When a Gradio server is deployed locally, the `localhost_aliases` variable includes "null" as a valid origin. This allows attackers to make unaut…

📅 Published: Oct. 10, 2024, 9:50 p.m. 🔄 Last Modified: Oct. 17, 2024, 4:46 p.m.
Total resulsts: 349182
Page 8323 of 34,919
« previous page » next page
Filters