Total
319 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-17574 | 1 Code-atlantic | 1 Popup Maker | 2019-10-18 | 6.4 MEDIUM | 9.1 CRITICAL |
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file"). | |||||
CVE-2017-0936 | 1 Nextcloud | 1 Nextcloud Server | 2019-10-09 | 4.9 MEDIUM | 5.7 MEDIUM |
Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user. | |||||
CVE-2019-17050 | 1 Thecontrolgroup | 1 Voyager | 2019-10-04 | 6.5 MEDIUM | 7.2 HIGH |
An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin privileges and Compass access can read or delete arbitrary files, such as the .env file. NOTE: a software maintainer has suggested a solution in which Compass is switched off in a production environment. | |||||
CVE-2017-15199 | 1 Kanboard | 1 Kanboard | 2019-10-02 | 4.0 MEDIUM | 4.3 MEDIUM |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of another user, as demonstrated by Name, Email, Identifier, and Description. | |||||
CVE-2017-15197 | 1 Kanboard | 1 Kanboard | 2019-10-02 | 4.0 MEDIUM | 4.3 MEDIUM |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of another user. | |||||
CVE-2017-15196 | 1 Kanboard | 1 Kanboard | 2019-10-02 | 4.0 MEDIUM | 4.3 MEDIUM |
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of another user. | |||||
CVE-2017-15195 | 1 Kanboard | 1 Kanboard | 2019-10-02 | 4.0 MEDIUM | 4.3 MEDIUM |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user. | |||||
CVE-2017-15202 | 1 Kanboard | 1 Kanboard | 2019-10-02 | 4.0 MEDIUM | 4.3 MEDIUM |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit columns of a private project of another user. | |||||
CVE-2017-15201 | 1 Kanboard | 1 Kanboard | 2019-10-02 | 4.0 MEDIUM | 4.3 MEDIUM |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tags of a private project of another user. | |||||
CVE-2017-15200 | 1 Kanboard | 1 Kanboard | 2019-10-02 | 4.0 MEDIUM | 4.3 MEDIUM |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of another user. | |||||
CVE-2017-15211 | 1 Kanboard | 1 Kanboard | 2019-10-02 | 4.0 MEDIUM | 4.3 MEDIUM |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of another user. | |||||
CVE-2017-15209 | 1 Kanboard | 1 Kanboard | 2019-10-02 | 4.0 MEDIUM | 4.3 MEDIUM |
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove attachments from a private project of another user. | |||||
CVE-2017-15208 | 1 Kanboard | 1 Kanboard | 2019-10-02 | 4.0 MEDIUM | 4.3 MEDIUM |
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove automatic actions from a private project of another user. | |||||
CVE-2017-15207 | 1 Kanboard | 1 Kanboard | 2019-10-02 | 4.0 MEDIUM | 4.3 MEDIUM |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tasks of a private project of another user. | |||||
CVE-2017-15206 | 1 Kanboard | 1 Kanboard | 2019-10-02 | 4.0 MEDIUM | 4.3 MEDIUM |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an internal link to a private project of another user. | |||||
CVE-2018-16608 | 1 Monstra | 1 Monstra | 2019-10-02 | 4.0 MEDIUM | 8.8 HIGH |
In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&action=edit&user_id=1, Insecure Direct Object Reference (IDOR). | |||||
CVE-2017-15204 | 1 Kanboard | 1 Kanboard | 2019-10-02 | 4.0 MEDIUM | 4.3 MEDIUM |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add automatic actions to a private project of another user. | |||||
CVE-2017-15203 | 1 Kanboard | 1 Kanboard | 2019-10-02 | 4.0 MEDIUM | 4.3 MEDIUM |
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove categories from a private project of another user. | |||||
CVE-2018-10211 | 1 Vaultize | 1 Enterprise File Sharing | 2019-10-02 | 5.0 MEDIUM | 5.3 MEDIUM |
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization when listing the history of another user via a modified "vaultize_session_id" value in a cookie. |