Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown
CVE-2021-30055
Disclosure Date: April 05, 2021 (last updated February 22, 2025)
A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year' parameter when running a report.
0
Attacker Value
Unknown
CVE-2021-30057
Disclosure Date: April 05, 2021 (last updated February 22, 2025)
A stored HTML injection vulnerability exists in Knowage Suite version 7.1. An attacker can inject arbitrary HTML in "/restful-services/2.0/analyticalDrivers" via the 'LABEL' and 'NAME' parameters.
0
Attacker Value
Unknown
CVE-2021-30056
Disclosure Date: April 05, 2021 (last updated February 22, 2025)
Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publish via the 'EXEC_FROM' parameter that can lead to data leakage.
0
Attacker Value
Unknown
CVE-2019-13349
Disclosure Date: September 05, 2019 (last updated November 27, 2024)
In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes.
0
Attacker Value
Unknown
CVE-2019-13188
Disclosure Date: September 05, 2019 (last updated November 27, 2024)
In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
0
Attacker Value
Unknown
CVE-2019-14278
Disclosure Date: September 05, 2019 (last updated November 27, 2024)
In Knowage through 6.1.1, an unauthenticated user can enumerated valid usernames via the ChangePwdServlet page.
0
Attacker Value
Unknown
CVE-2019-13190
Disclosure Date: September 05, 2019 (last updated November 27, 2024)
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.
0
Attacker Value
Unknown
CVE-2019-13348
Disclosure Date: August 28, 2019 (last updated November 27, 2024)
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.
0
Attacker Value
Unknown
CVE-2019-13189
Disclosure Date: August 28, 2019 (last updated November 27, 2024)
In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.
0
Attacker Value
Unknown
CVE-2018-12353
Disclosure Date: June 13, 2018 (last updated November 26, 2024)
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name field to the "Business Model's Catalogue" catalogue.
0