Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2024-41372

Disclosure Date: August 29, 2024 (last updated September 05, 2024)
Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php.
Attacker Value
Unknown

CVE-2024-41371

Disclosure Date: August 29, 2024 (last updated September 05, 2024)
Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php.
Attacker Value
Unknown

CVE-2024-41370

Disclosure Date: August 29, 2024 (last updated September 05, 2024)
Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php.
Attacker Value
Unknown

CVE-2022-1909

Disclosure Date: May 27, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200.
Attacker Value
Unknown

CVE-2022-1699

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.
Attacker Value
Unknown

CVE-2022-1698

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Allowing long password leads to denial of service in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.
Attacker Value
Unknown

CVE-2022-1347

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub repository causefx/organizr prior to 2.1.1810. Account takeover and privilege escalation
Attacker Value
Unknown

CVE-2022-1345

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
Attacker Value
Unknown

CVE-2022-1346

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
Attacker Value
Unknown

CVE-2022-1344

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.