VendorsPersonal Management Systempersonal_management_system1.4.64
Vulnerabilities

Personal Management System Personal Management System 1.4.64

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2024-29319
Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and DNS requests to a server that the attacker controls.
Published 2024-07-05 · Modified
9.8EPSS 0.004
CVE-2023-43838
An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.
Published 2023-10-04 · Modified
7.8EPSS 0.006
CVE-2024-29318
Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code.
Published 2024-07-05 · Modified
5.4EPSS 0.003