2 results (0.005 seconds)
CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0
CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 0

CVE-2023-26089
https://notcve.org/view.php?id=CVE-2023-26089
02 May 2023 — European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5. • https://iuclid6.echa.europa.eu • CWE-798: Use of Hard-coded Credentials •

CVE-2023-26546
https://notcve.org/view.php?id=CVE-2023-26546
02 May 2023 — European Chemicals Agency IUCLID before 6.27.6 allows remote authenticated users to execute arbitrary code via Server Side Template Injection (SSTI) with a crafted template file. The attacker must have template manager permission. • https://iuclid6.echa.europa.eu • CWE-94: Improper Control of Generation of Code ('Code Injection') •