Loading product vulnerabilities…
Total
2
Critical
1
High
1
Medium
0
CISA KEV
0
python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.
The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.