Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown

CVE-2020-9389

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid usernames.
Attacker Value
Unknown

CVE-2020-9390

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content in iframe or by uploading an SVG that contained a script.
Attacker Value
Unknown

CVE-2020-9388

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.