RSS   Vulnerabilities for 'Openmaint'   RSS

2021-03-15
 
CVE-2021-27695

CWE-79
 

 
Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters.

 
2021-01-26
 
CVE-2020-24549

CWE-434
 

 
openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server.

 


Copyright 2024, cxsecurity.com

 

Back to Top