Show filters
144 Total Results
Displaying 21-30 of 144
Sort by:
Attacker Value
Unknown

CVE-2021-43958

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing user credentials for authentication via a improper restriction of excess authentication attempts vulnerability.
Attacker Value
Unknown

CVE-2021-43956

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability.
Attacker Value
Unknown

CVE-2021-43954

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.
Attacker Value
Unknown

CVE-2021-45018

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Index/addmenu.htmland then the .html file on the website that uses this editor (the file suffix is allowed).
Attacker Value
Unknown

CVE-2021-45017

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor; you can specify the menu url address as your malicious url address in the Add Menu column.
Attacker Value
Unknown

CVE-2021-33981

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
An insecure, direct object vulnerability in hunting/fishing license retrieval function of the "Fish | Hunt FL" iOS app versions 3.8.0 and earlier allows a remote authenticated attacker to retrieve other people's personal information and images of their hunting/fishing licenses.
Attacker Value
Unknown

CVE-2021-33982

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
An insufficient session expiration vulnerability exists in the "Fish | Hunt FL" iOS app version 3.8.0 and earlier, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions.
Attacker Value
Unknown

CVE-2021-3314

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Attacker Value
Unknown

CVE-2020-23962

Disclosure Date: June 23, 2021 (last updated February 22, 2025)
A cross site scripting (XSS) vulnerability in Catfish CMS 4.9.90 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "announcement_gonggao" parameter.
Attacker Value
Unknown

CVE-2020-29446

Disclosure Date: December 10, 2020 (last updated February 22, 2025)
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.