mind records
3 published records for vendor mind.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2020-25398Proof of concept | CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.mind · imind server · CWE-1236 | High8.8 | — | 2.0% | Nov 5, 2020 |
32Monitor | CVE-2020-24765No exploit | InterMind iMind Server through 3.13.65 allows remote unauthenticated attackers to read the self-diagnostic archive via a direct api/rs/monitmind · imind server · CWE-425 | High7.5 | — | 6.8% | Oct 20, 2020 |
31Monitor | CVE-2020-25399Proof of concept | Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chamind · imind server · CWE-79 | High7.8 | — | 1.0% | Nov 5, 2020 |
- CVE-2020-2539836Monitor
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
HighCVSS 8.8Proof of conceptEPSS 2%mind · imind serverNov 5, 2020
- CVE-2020-2476532Monitor
InterMind iMind Server through 3.13.65 allows remote unauthenticated attackers to read the self-diagnostic archive via a direct api/rs/monit
HighCVSS 7.5No exploitEPSS 7%mind · imind serverOct 20, 2020
- CVE-2020-2539931Monitor
Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the cha
HighCVSS 7.8Proof of conceptEPSS 1%mind · imind serverNov 5, 2020