CVE-2022-44953
- EPSS 0.2%
- Veröffentlicht 02.12.2022 20:15:14
- Zuletzt bearbeitet 24.04.2025 20:15:28
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /linkedcontent/listfiles.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the N...
CVE-2022-44291
- EPSS 63.22%
- Veröffentlicht 02.12.2022 20:15:13
- Zuletzt bearbeitet 24.04.2025 21:15:20
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
CVE-2022-44290
- EPSS 63.22%
- Veröffentlicht 02.12.2022 20:15:13
- Zuletzt bearbeitet 24.04.2025 21:15:20
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
CVE-2021-36609
- EPSS 0.19%
- Veröffentlicht 16.06.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:52
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder.php.
CVE-2021-36608
- EPSS 0.19%
- Veröffentlicht 16.06.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:51
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php.
CVE-2021-43481
- EPSS 0.57%
- Veröffentlicht 20.04.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:18
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.
CVE-2021-41920
- EPSS 1.98%
- Veröffentlicht 08.10.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:57
webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker t...
CVE-2021-41919
- EPSS 2.18%
- Veröffentlicht 08.10.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:57
webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is working by adding or replacing a personal profile picture. The affected endpoint is /includes/upload.php on...
CVE-2021-41918
- EPSS 0.32%
- Veröffentlicht 08.10.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:57
webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the platform users and administrator...
CVE-2021-41917
- EPSS 0.32%
- Veröffentlicht 08.10.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:56
webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or editing a client name in the clients section, due to incorrect sanitization of user-supplied data and achieve a Stored Cross-Site Scri...