Show filters
198 Total Results
Displaying 11-20 of 198
Sort by:
Attacker Value
Unknown

CVE-2023-30097

Disclosure Date: May 04, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the private task field.
Attacker Value
Unknown

CVE-2023-30096

Disclosure Date: May 04, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user information field.
Attacker Value
Unknown

CVE-2023-30095

Disclosure Date: May 04, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the channel description field.
Attacker Value
Unknown

CVE-2022-41708

Disclosure Date: October 19, 2022 (last updated October 08, 2023)
Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible because the application does not validate permissions correctly.
Attacker Value
Unknown

CVE-2022-41707

Disclosure Date: October 19, 2022 (last updated October 08, 2023)
Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access sensitive data of any user of the application. This is possible because the application exposes user data to the public.
Attacker Value
Unknown

CVE-2022-28218

Disclosure Date: April 26, 2022 (last updated October 07, 2023)
An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-factor authentication (2FA).
Attacker Value
Unknown

CVE-2021-43430

Disclosure Date: April 07, 2022 (last updated October 07, 2023)
An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan files.
Attacker Value
Unknown

CVE-2020-20093

Disclosure Date: March 23, 2022 (last updated October 07, 2023)
The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.
Attacker Value
Unknown

CVE-2021-45889

Disclosure Date: March 13, 2022 (last updated October 07, 2023)
An issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as demonstrated by private/index.jsp?partners/ShowNonLocalPartners.do?localID= or private/index.jsp or private/index.jsp?database/databaseTab.jsp or private/index.jsp?activation/activationMainTab.jsp or private/index.jsp?communication/serverTab.jsp or private/index.jsp?emailNotification/notificationTab.jsp.
Attacker Value
Unknown

CVE-2021-45888

Disclosure Date: March 13, 2022 (last updated October 07, 2023)
An issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of every page of the web application is vulnerable to XSS: it allows injection of JavaScript into its nodes. Creating such nodes is only possible for users who have the role Configuration Administrator or Administrator.