Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2023-1783

Disclosure Date: June 23, 2023 (last updated February 25, 2025)
OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible because the application does not properly validate the HTML content to be converted to PDF.
Attacker Value
Unknown

CVE-2023-0738

Disclosure Date: April 04, 2023 (last updated February 24, 2025)
OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the application returns malicious user input in the response with the content-type set to text/html.
Attacker Value
Unknown

CVE-2023-0624

Disclosure Date: February 09, 2023 (last updated February 24, 2025)
OrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the application returns malicious user input in the response with the content-type set to text/html.
Attacker Value
Unknown

CVE-2023-0454

Disclosure Date: February 01, 2023 (last updated February 24, 2025)
OrangeScrum version 2.0.11 allows an authenticated external attacker to delete arbitrary local files from the server. This is possible because the application uses an unsanitized attacker-controlled parameter to construct an internal path.
Attacker Value
Unknown

CVE-2023-0164

Disclosure Date: January 18, 2023 (last updated February 24, 2025)
OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because the application injects an attacker-controlled parameter into a system function.