Serpico Project

Serpico

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.46%
  • Veröffentlicht 07.05.2020 16:15:11
  • Zuletzt bearbeitet 21.11.2024 05:00:04

An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin authenticated users. This means that an attacker with a user account can retrieve all of the attachments of all users (including admi...

  • EPSS 0.14%
  • Veröffentlicht 15.01.2020 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:32

An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. It does not use CSRF Tokens to mitigate against CSRF; it uses the Origin header (which must match the request origin). This is problematic in conjunction wit...

  • EPSS 0.24%
  • Veröffentlicht 15.01.2020 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:32

An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/list_user allows stored XSS via the auth_type parameter.

  • EPSS 0.24%
  • Veröffentlicht 15.01.2020 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:32

An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The User Type on the admin/list_user page allows stored XSS via the type parameter.

  • EPSS 0.21%
  • Veröffentlicht 15.01.2020 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:32

An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using interfaces outside the Change Password screen. Thus, requiring the admin ...

  • EPSS 0.32%
  • Veröffentlicht 15.01.2020 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:32

An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/add_user/UID allows stored XSS via the author parameter.

  • EPSS 0.24%
  • Veröffentlicht 15.01.2020 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:32

An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The Add Collaborator allows unlimited data via the author parameter, even if the data does not match anything in the database.