Petereport Project's vulnerability profile concentrates in its web-based reporting application, with the durable signal centered on web-layer input-handling issues including cross-site scripting and cross-site request forgery. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Petereport Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23052MEDIUM PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, reports and findings on the app | Mar 3, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-23051MEDIUM PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack Tree' by modifying the 'svg_file' parameter. | Mar 3, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-25220MEDIUM PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code inside the markdown descriptions while creating a product, report or finding. | Mar 3, 2022 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Petereport Project.
Media articles that mention a CVE ID that affects a product developed by Petereport Project — matched by CVE ID, not by vendor name.