Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown

CVE-2021-30055

Disclosure Date: April 05, 2021 (last updated February 22, 2025)
A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year' parameter when running a report.
Attacker Value
Unknown

CVE-2021-30057

Disclosure Date: April 05, 2021 (last updated February 22, 2025)
A stored HTML injection vulnerability exists in Knowage Suite version 7.1. An attacker can inject arbitrary HTML in "/restful-services/2.0/analyticalDrivers" via the 'LABEL' and 'NAME' parameters.
Attacker Value
Unknown

CVE-2021-30056

Disclosure Date: April 05, 2021 (last updated February 22, 2025)
Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publish via the 'EXEC_FROM' parameter that can lead to data leakage.
Attacker Value
Unknown

CVE-2019-13349

Disclosure Date: September 05, 2019 (last updated November 27, 2024)
In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes.
0
Attacker Value
Unknown

CVE-2019-13188

Disclosure Date: September 05, 2019 (last updated November 27, 2024)
In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
0
Attacker Value
Unknown

CVE-2019-14278

Disclosure Date: September 05, 2019 (last updated November 27, 2024)
In Knowage through 6.1.1, an unauthenticated user can enumerated valid usernames via the ChangePwdServlet page.
0
Attacker Value
Unknown

CVE-2019-13190

Disclosure Date: September 05, 2019 (last updated November 27, 2024)
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.
0
Attacker Value
Unknown

CVE-2019-13348

Disclosure Date: August 28, 2019 (last updated November 27, 2024)
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.
0
Attacker Value
Unknown

CVE-2019-13189

Disclosure Date: August 28, 2019 (last updated November 27, 2024)
In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.
0
Attacker Value
Unknown

CVE-2018-12353

Disclosure Date: June 13, 2018 (last updated November 26, 2024)
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name field to the "Business Model's Catalogue" catalogue.
0