Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown
CVE-2024-48708
Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php under action = adduser/edituser.
0
Attacker Value
Unknown
CVE-2024-48707
Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php file.
0
Attacker Value
Unknown
CVE-2024-48706
Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.
0
Attacker Value
Unknown
CVE-2024-46240
Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters under action=addcust within admin.php file.
0
Attacker Value
Unknown
CVE-2021-3298
Disclosure Date: January 29, 2021 (last updated February 22, 2025)
Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.
0
Attacker Value
Unknown
CVE-2020-13655
Disclosure Date: August 31, 2020 (last updated February 22, 2025)
An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are reflected.
0
Attacker Value
Unknown
CVE-2015-0258
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension.
0
Attacker Value
Unknown
CVE-2013-5027
Disclosure Date: December 27, 2019 (last updated November 27, 2024)
Collabtive 1.0 has incorrect access control
0
Attacker Value
Unknown
CVE-2019-8935
Disclosure Date: February 19, 2019 (last updated November 27, 2024)
Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.
0
Attacker Value
Unknown
CVE-2014-3247
Disclosure Date: May 15, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php.
0