RSS   Vulnerabilities for 'Appspace'   RSS

2021-04-14
 
CVE-2021-27990

CWE-287
 

 
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities.

 
 
CVE-2021-27989

CWE-79
 

 
Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.

 
2021-02-25
 
CVE-2021-27670

CWE-918
 

 
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

 
2021-02-22
 
CVE-2021-27564

CWE-79
 

 
A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups section of the network tab, it is stored as the group name. Whenever another member visits that group, this payload executes.

 

 >>> Vendor: Appspace 2 Products
On-prem
Appspace


Copyright 2021, cxsecurity.com

 

Back to Top