RSS   Vulnerabilities for 'Appspace'   RSS

2021-02-25
 
CVE-2021-27670

CWE-918
 

 
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

 
2021-02-22
 
CVE-2021-27564

CWE-79
 

 
A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups section of the network tab, it is stored as the group name. Whenever another member visits that group, this payload executes.

 

 >>> Vendor: Appspace 2 Products
On-prem
Appspace


Copyright 2021, cxsecurity.com

 

Back to Top