Huly
Hcengineering · 2 CVEs
CVE-2024-48450
MEDIUM
An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploadi…
Oct 25, 2024
CVE-2024-27707
MEDIUM
Server Side Request Forgery (SSRF) vulnerability in hcengineering Huly Platform v.0.6.202 allows attackers to run arbit…
Mar 7, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-48450 | An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into chat group. | MEDIUM | 0.53% | Oct 25, 2024 |
| CVE-2024-27707 | Server Side Request Forgery (SSRF) vulnerability in hcengineering Huly Platform v.0.6.202 allows attackers to run arbitrary code via upload of crafted SVG file. | MEDIUM | 0.33% | Mar 7, 2024 |
Showing 1 to 2 of 2 CVEs