Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2024-52399

Disclosure Date: November 16, 2024 (last updated November 17, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in Clarisse K. Writer Helper allows Upload a Web Shell to a Web Server.This issue affects Writer Helper: from n/a through 3.1.6.
0
Attacker Value
Unknown

CVE-2024-27790

Disclosure Date: May 14, 2024 (last updated December 21, 2024)
Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileMaker Server 20.3.2 by validating transactions before replying to client requests.
Attacker Value
Unknown

CVE-2023-42955

Disclosure Date: May 14, 2024 (last updated December 21, 2024)
Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by eliminating the send of Admin Role passwords in the Node.js socket.
Attacker Value
Unknown

CVE-2024-27794

Disclosure Date: April 15, 2024 (last updated December 21, 2024)
Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login endpoint. The vulnerability was resolved in FileMaker Server 20.3.2 by escaping the HTML contents of the login error message on the login page.
Attacker Value
Unknown

CVE-2023-42954

Disclosure Date: March 21, 2024 (last updated December 21, 2024)
A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in requests.
Attacker Value
Unknown

CVE-2023-42920

Disclosure Date: March 19, 2024 (last updated December 21, 2024)
Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS.
Attacker Value
Unknown

CVE-2021-44147

Disclosure Date: November 22, 2021 (last updated February 23, 2025)
An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files via a crafted XML/Excel document and perform server-side request forgery attacks.
Attacker Value
Unknown

CVE-2014-8347

Disclosure Date: February 11, 2020 (last updated February 21, 2025)
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious user obtain elevated privileges.