Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2024-6097
Disclosure Date: February 12, 2025 (last updated February 13, 2025)
In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.
0
Attacker Value
Unknown
CVE-2024-11626
Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
0
Attacker Value
Unknown
CVE-2024-11625
Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
0
Attacker Value
Unknown
CVE-2024-9999
Disclosure Date: November 12, 2024 (last updated November 13, 2024)
In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
0
Attacker Value
Unknown
CVE-2024-9825
Disclosure Date: October 28, 2024 (last updated October 29, 2024)
The Chef Habitat builder-api on-prem-builder package with any version lower than habitat/builder-api/10315/20240913162802 is vulnerable to indirect object reference (IDOR) by un-authorized deletion of personal token. Habitat builder consumes builder-api habitat package as a dependency and the vulnerability was specifically due to builder-api habitat package.
The fix was made available in habitat/builder-api/10315/20240913162802 and all the subsequent versions after that. We would recommend user to always use on-prem stable channel.
0
Attacker Value
Unknown
CVE-2024-4882
Disclosure Date: July 08, 2024 (last updated July 09, 2024)
The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.
0