RSS   Vulnerabilities for 'Cloverdx'   RSS

2021-12-01
 
CVE-2021-42776

CWE-611
 

 
CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.

 
2021-06-09
 
CVE-2021-29995

CWE-352
 

 
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.

 
 
CVE-2021-30133

CWE-79
 

 
A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the sessionToken parameter of multiple methods in Simple HTTP API. This is resolved in 5.9.1 and 5.10.

 


Copyright 2024, cxsecurity.com

 

Back to Top