Show filters
74 Total Results
Displaying 11-20 of 74
Sort by:
Attacker Value
Unknown

CVE-2024-23349

Disclosure Date: February 22, 2024 (last updated December 21, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. XSS attack when user enters summary. A logged-in user, when modifying their own submitted question, can input malicious code in the summary to create such an attack. Users are recommended to upgrade to version [1.2.5], which fixes the issue.
Attacker Value
Unknown

CVE-2024-22393

Disclosure Date: February 22, 2024 (last updated February 14, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content. Users are recommended to upgrade to version [1.2.5], which fixes the issue.
0
Attacker Value
Unknown

CVE-2023-49619

Disclosure Date: January 10, 2024 (last updated January 18, 2024)
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and will only increase the number of questions bookmarked once. However, repeat submissions through the script can increase the number of collection of the question many times. Users are recommended to upgrade to version [1.2.1], which fixes the issue.
Attacker Value
Unknown

CVE-2023-4815

Disclosure Date: September 07, 2023 (last updated February 25, 2025)
Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3.
Attacker Value
Unknown

CVE-2023-4127

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Race Condition within a Thread in GitHub repository answerdev/answer prior to v1.1.1.
Attacker Value
Unknown

CVE-2023-4126

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.
Attacker Value
Unknown

CVE-2023-4125

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.
Attacker Value
Unknown

CVE-2023-4124

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1.
Attacker Value
Unknown

CVE-2021-4408

Disclosure Date: July 12, 2023 (last updated November 09, 2023)
The DW Question & Answer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.8. This is due to missing or incorrect nonce validation on the update_answer() function. This makes it possible for unauthenticated attackers to update answers to questions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2023-2590

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Missing Authorization in GitHub repository answerdev/answer prior to 1.0.9.