appspace records
6 published records for vendor appspace.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2021-27670Proof of concept | Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.appspace · appspace · CWE-918 | Critical9.8 | — | 61.3% | Feb 24, 2021 |
30Monitor | CVE-2021-27990No exploit | Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the fraappspace · appspace · CWE-287 | High7.5 | — | 1.4% | Apr 14, 2021 |
26Monitor | CVE-2021-27704No exploit | Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.appspace · appspace · CWE-352 | Medium6.5 | — | 0.4% | Nov 12, 2024 |
24Monitor | CVE-2020-5393No exploit | In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.appspace · on-prem · CWE-79 | Medium6.1 | — | 0.7% | Jan 7, 2020 |
21Monitor | CVE-2021-27564No exploit | A stored XSS issue exists in Appspace 6.2.4.appspace · appspace · CWE-79 | Medium5.4 | — | 0.5% | Feb 22, 2021 |
21Monitor | CVE-2021-27989No exploit | Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.appspace · appspace · CWE-79 | Medium5.4 | — | 0.5% | Apr 14, 2021 |
- CVE-2021-2767057Plan
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.
CriticalCVSS 9.8Proof of conceptEPSS 61%appspace · appspaceFeb 24, 2021
- CVE-2021-2799030Monitor
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the fra
HighCVSS 7.5No exploitEPSS 1%appspace · appspaceApr 14, 2021
- CVE-2021-2770426Monitor
Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.
MediumCVSS 6.5No exploitEPSS 0%appspace · appspaceNov 12, 2024
- CVE-2020-539324Monitor
In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.
MediumCVSS 6.1No exploitEPSS 1%appspace · on-premJan 7, 2020
- CVE-2021-2756421Monitor
A stored XSS issue exists in Appspace 6.2.4.
MediumCVSS 5.4No exploitEPSS 1%appspace · appspaceFeb 22, 2021
- CVE-2021-2798921Monitor
Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.
MediumCVSS 5.4No exploitEPSS 0%appspace · appspaceApr 14, 2021