Webtareas Project

Webtareas

25 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 75.7%
  • Veröffentlicht 02.12.2022 20:15:13
  • Zuletzt bearbeitet 24.04.2025 21:15:20

webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 16.06.2022 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:13:51

Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 16.06.2022 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:13:52

Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder.php.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 20.04.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:18

An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.

Exploit
  • EPSS 2.59%
  • Veröffentlicht 08.10.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:26:57

webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker t...

Exploit
  • EPSS 1.53%
  • Veröffentlicht 08.10.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:26:57

webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is working by adding or replacing a personal profile picture. The affected endpoint is /includes/upload.php on...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 08.10.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:26:57

webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the platform users and administrator...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 08.10.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:26:56

webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or editing a client name in the clients section, due to incorrect sanitization of user-supplied data and achieve a Stored Cross-Site Scri...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 08.10.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:26:56

A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profile and add a new user to the new profile. without the victim's knowledge, by enticing an authenticated...

Exploit
  • EPSS 1.39%
  • Veröffentlicht 18.08.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 05:13:34

Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files.