Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2023-35046

Disclosure Date: December 13, 2024 (last updated February 27, 2025)
Missing Authorization vulnerability in Dynamic.ooo Dynamic Visibility for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamic Visibility for Elementor: from n/a through 5.0.5.
0
Attacker Value
Unknown

CVE-2024-48708

Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php under action = adduser/edituser.
Attacker Value
Unknown

CVE-2024-48707

Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php file.
Attacker Value
Unknown

CVE-2024-48706

Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.
Attacker Value
Unknown

CVE-2024-46240

Disclosure Date: October 22, 2024 (last updated February 26, 2025)
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters under action=addcust within admin.php file.
Attacker Value
Unknown

CVE-2021-3298

Disclosure Date: January 29, 2021 (last updated February 22, 2025)
Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.
Attacker Value
Unknown

CVE-2020-13655

Disclosure Date: August 31, 2020 (last updated February 22, 2025)
An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are reflected.
Attacker Value
Unknown

CVE-2015-0258

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension.
Attacker Value
Unknown

CVE-2013-5027

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
Collabtive 1.0 has incorrect access control
Attacker Value
Unknown

CF CLI writes the client id and secret to config file

Disclosure Date: August 05, 2019 (last updated November 27, 2024)
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
0