Spaceapplications

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 8
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-46470

    Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via crafted telecommand in the timeline view of the ArchiveBrowser.

    Last Modified: Nov 21, 2024
    Published: Nov 20, 2023

    CVE-2023-46471

    Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via the text variable scriptContainer of the ScriptViewer.

    Last Modified: Jun 10, 2025
    Published: Nov 20, 2023

    CVE-2023-47311

    An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking.

    Last Modified: Nov 21, 2024
    Published: Nov 20, 2023

    CVE-2023-45280

    Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload an HTML file containing arbitrary JavaScript and then navigate to it. Once the user opens the file, the browser will execute the arbitrary JavaScript.

    Last Modified: Nov 21, 2024
    Published: Oct 19, 2023

    CVE-2023-45277

    Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.

    Last Modified: Nov 21, 2024
    Published: Oct 19, 2023
    Items Per Page
    Spaceapplications Vulnerabilities & Security CVEs | CVE-DB