Ponton

X/p Messenger

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.15%
  • Veröffentlicht 13.03.2022 02:15:07
  • Zuletzt bearbeitet 21.11.2024 06:33:11

An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable to a weakened version of CSRF, where an arbitrary token of a low-privileged user (such as operator) can be used ...

Exploit
  • EPSS 5.52%
  • Veröffentlicht 13.03.2022 02:15:07
  • Zuletzt bearbeitet 21.11.2024 06:33:11

An issue was discovered in PONTON X/P Messenger before 3.11.2. Due to path traversal in private/SchemaSetUpload.do for uploaded ZIP files, an executable script can be uploaded by web application administrators, giving the attacker remote code executi...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 13.03.2022 02:15:07
  • Zuletzt bearbeitet 21.11.2024 06:33:12

An issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of every page of the web application is vulnerable to XSS: it allows injection of JavaScript into its nodes. Creating such nodes is only...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 13.03.2022 02:15:07
  • Zuletzt bearbeitet 21.11.2024 06:33:12

An issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as demonstrated by private/index.jsp?partners/ShowNonLocalPartners.do?localID= or private/index.jsp or private/index.jsp?database/databa...