Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown
CVE-2021-42562
Disclosure Date: January 12, 2022 (last updated February 23, 2025)
An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other components that should only be accessible by admin users.
0
Attacker Value
Unknown
CVE-2021-42561
Disclosure Date: January 12, 2022 (last updated February 23, 2025)
An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesis "$()" ) in order to escape the current command and execute arbitrary shell commands.
0
Attacker Value
Unknown
CVE-2021-42560
Disclosure Date: January 12, 2022 (last updated February 23, 2025)
An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe manner and can be leveraged for XXE attacks (e.g., File Exfiltration, Server Side Request Forgery, Out of Band Exfiltration, etc.).
0
Attacker Value
Unknown
CVE-2021-24896
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
0
Attacker Value
Unknown
CVE-2020-19907
Disclosure Date: July 12, 2021 (last updated February 23, 2025)
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.
0
Attacker Value
Unknown
CVE-2020-14462
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
CALDERA 2.7.0 allows XSS via the Operation Name box.
0
Attacker Value
Unknown
CVE-2020-10807
Disclosure Date: March 22, 2020 (last updated February 21, 2025)
auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host header.
0
Attacker Value
Unknown
CVE-2018-7747
Disclosure Date: April 20, 2018 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a greeting message, (2) the email transaction log, or (3) an imported form.
0
Attacker Value
Unknown
CVE-2014-2936
Disclosure Date: May 08, 2014 (last updated October 05, 2023)
The directory manager in Caldera 9.20 allows remote attackers to conduct variable-injection attacks in the global scope via (1) the maindir_hotfolder parameter to dirmng/index.php, or an unspecified parameter to (2) PPD/index.php, (3) dirmng/docmd.php, or (4) dirmng/param.php.
0
Attacker Value
Unknown
CVE-2014-2934
Disclosure Date: May 08, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the tr parameter to (1) costview2/jobs.php or (2) costview2/printers.php.
0