Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2024-48708

Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php under action = adduser/edituser.
Attacker Value
Unknown

CVE-2024-48707

Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php file.
Attacker Value
Unknown

CVE-2024-48706

Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.
Attacker Value
Unknown

CVE-2024-46240

Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters under action=addcust within admin.php file.
Attacker Value
Unknown

CVE-2021-3298

Disclosure Date: January 29, 2021 (last updated February 22, 2025)
Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.
Attacker Value
Unknown

CVE-2019-8935

Disclosure Date: February 19, 2019 (last updated November 27, 2024)
Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.
0