Skip to content
Noroxi

appspace records

6 published records for vendor appspace.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

6 records
  • Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

    CriticalCVSS 9.8Proof of conceptEPSS 61%

    appspace · appspaceFeb 24, 2021

  • Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the fra

    HighCVSS 7.5No exploitEPSS 1%

    appspace · appspaceApr 14, 2021

  • Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.

    MediumCVSS 6.5No exploitEPSS 0%

    appspace · appspaceNov 12, 2024

  • CVE-2020-5393
    24Monitor

    In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.

    MediumCVSS 6.1No exploitEPSS 1%

    appspace · on-premJan 7, 2020

  • A stored XSS issue exists in Appspace 6.2.4.

    MediumCVSS 5.4No exploitEPSS 1%

    appspace · appspaceFeb 22, 2021

  • Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.

    MediumCVSS 5.4No exploitEPSS 0%

    appspace · appspaceApr 14, 2021