CVEs
VLC Media Player - Vulnerability report pending disclosure
Horilla - Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation
Horilla - Unauthorized Document Overwrite via File Upload Endpoint
Horilla - Insecure Direct Object Reference at /employee/view-file/
YesWiki - Persistant Blind XSS at "/?BazaR&vue=consulter"
Intermesh GroupOffice - Reflected XSS in Look and feel section of the application
Intermesh GroupOffice - Blind XSS using user's First and Last names field executed on Synchronization's Address books
Intermesh GroupOffice - Stored XSS in Tasks Comment Section
Intermesh GroupOffice - DOM-Based XSS in all Date Input Fields Allow Arbitrary JavaScript Execution
Intermesh GroupOffice - Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions
| CVE Designation | Vulnerability Summary | Severity | Advisory |
|---|---|---|---|
|
|
Reflected XSS in NASA JPL Solar System Simulator |
MEDIUM | open_in_new Advisory |
|
|
VLC Media Player - Vulnerability report pending disclosure |
MEDIUM | Confidential / Vendor Patch |
|
Horilla - Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation |
HIGH | open_in_new Advisory |
|
Horilla - Unauthorized Document Overwrite via File Upload Endpoint |
HIGH | open_in_new Advisory |
|
Horilla - Insecure Direct Object Reference at /employee/view-file/ |
HIGH | open_in_new Advisory |
|
|
YesWiki - Persistant Blind XSS at "/?BazaR&vue=consulter" |
CRITICAL | open_in_new Advisory |
|
|
Intermesh GroupOffice - Reflected XSS in Look and feel section of the application |
MEDIUM | open_in_new Advisory |
|
|
Intermesh GroupOffice - Blind XSS using user's First and Last names field executed on Synchronization's Address books |
HIGH | open_in_new Advisory |
|
|
Intermesh GroupOffice - Stored XSS in Tasks Comment Section |
MEDIUM | open_in_new Advisory |
|
|
Intermesh GroupOffice - DOM-Based XSS in all Date Input Fields Allow Arbitrary JavaScript Execution |
CRITICAL | open_in_new Advisory |
|
|
Intermesh GroupOffice - Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions |
CRITICAL | open_in_new Advisory |