Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown

CVE-2024-48708

Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php under action = adduser/edituser.
Attacker Value
Unknown

CVE-2024-48707

Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php file.
Attacker Value
Unknown

CVE-2024-48706

Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.
Attacker Value
Unknown

CVE-2024-46240

Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters under action=addcust within admin.php file.
Attacker Value
Unknown

CVE-2021-3298

Disclosure Date: January 29, 2021 (last updated February 22, 2025)
Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.
Attacker Value
Unknown

CVE-2020-13655

Disclosure Date: August 31, 2020 (last updated February 22, 2025)
An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are reflected.
Attacker Value
Unknown

CVE-2015-0258

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension.
Attacker Value
Unknown

CVE-2013-5027

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
Collabtive 1.0 has incorrect access control
Attacker Value
Unknown

CVE-2019-8935

Disclosure Date: February 19, 2019 (last updated November 27, 2024)
Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.
0
Attacker Value
Unknown

CVE-2014-3247

Disclosure Date: May 15, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php.
0