Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2024-26135
Disclosure Date: February 20, 2024 (last updated January 17, 2025)
MeshCentral is a full computer management web site. Versions prior to 1.1.21 a cross-site websocket hijacking (CSWSH) vulnerability within the control.ashx endpoint. This component is the primary mechanism used within MeshCentral to perform administrative actions on the server. The vulnerability is exploitable when an attacker is able to convince a victim end-user to click on a malicious link to a page hosting an attacker-controlled site. The attacker can then originate a cross-site websocket connection using client-side JavaScript code to connect to `control.ashx` as the victim user within MeshCentral. Version 1.1.21 contains a patch for this issue.
0
Attacker Value
Unknown
CVE-2023-51838
Disclosure Date: February 02, 2024 (last updated February 10, 2024)
Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm.
0
Attacker Value
Unknown
CVE-2023-51837
Disclosure Date: January 30, 2024 (last updated February 06, 2024)
Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation.
0
Attacker Value
Unknown
CVE-2023-51842
Disclosure Date: January 29, 2024 (last updated February 07, 2024)
An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16.
0