appspace kayıtları
appspace üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2021-27670Kavram kanıtı | Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.appspace · appspace · CWE-918 | Kritik9,8 | — | %61,3 | 24 Şub 2021 |
30İzleyin | CVE-2021-27990İstismar yok | Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the fraappspace · appspace · CWE-287 | Yüksek7,5 | — | %1,4 | 14 Nis 2021 |
26İzleyin | CVE-2021-27704İstismar yok | Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.appspace · appspace · CWE-352 | Orta6,5 | — | %0,4 | 12 Kas 2024 |
24İzleyin | CVE-2020-5393İstismar yok | In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.appspace · on-prem · CWE-79 | Orta6,1 | — | %0,7 | 7 Oca 2020 |
21İzleyin | CVE-2021-27564İstismar yok | A stored XSS issue exists in Appspace 6.2.4.appspace · appspace · CWE-79 | Orta5,4 | — | %0,5 | 22 Şub 2021 |
21İzleyin | CVE-2021-27989İstismar yok | Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.appspace · appspace · CWE-79 | Orta5,4 | — | %0,5 | 14 Nis 2021 |
- CVE-2021-2767057Planlayın
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.
KritikCVSS 9,8Kavram kanıtıEPSS %61appspace · appspace24 Şub 2021
- CVE-2021-2799030İzleyin
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the fra
YüksekCVSS 7,5İstismar yokEPSS %1appspace · appspace14 Nis 2021
- CVE-2021-2770426İzleyin
Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.
OrtaCVSS 6,5İstismar yokEPSS %0appspace · appspace12 Kas 2024
- CVE-2020-539324İzleyin
In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.
OrtaCVSS 6,1İstismar yokEPSS %1appspace · on-prem7 Oca 2020
- CVE-2021-2756421İzleyin
A stored XSS issue exists in Appspace 6.2.4.
OrtaCVSS 5,4İstismar yokEPSS %1appspace · appspace22 Şub 2021
- CVE-2021-2798921İzleyin
Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.
OrtaCVSS 5,4İstismar yokEPSS %0appspace · appspace14 Nis 2021