Archerirm

Archer

28 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Published 06.05.2024 16:15:13
  • Last modified 25.03.2025 17:15:56

An issue was discovered in Archer Platform 6 before 2024.04. Authentication was mishandled because lock did not terminate an existing session. 6.14 P3 (6.14.0.3) is also a fixed release.

  • EPSS 0.23%
  • Published 06.05.2024 16:15:13
  • Last modified 18.03.2025 14:54:25

An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript c...

  • EPSS 0.69%
  • Published 06.05.2024 16:15:13
  • Last modified 18.03.2025 17:30:14

An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. The login banner in the Archer Control Panel (ACP) did not previously escape content appropriately. 6.14 P3 (6.14.0.3) is also a ...

  • EPSS 0.23%
  • Published 06.05.2024 16:15:13
  • Last modified 28.03.2025 19:15:22

An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript c...

  • EPSS 0.27%
  • Published 08.03.2024 02:15:50
  • Last modified 18.03.2025 17:27:14

Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML or JavaScript code in a trusted applic...

  • EPSS 0.1%
  • Published 08.03.2024 02:15:50
  • Last modified 26.03.2025 17:15:24

Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a sensitive information disclosure vulnerability. An unauthenticated attacker could potentially obtain access to sensitive information via an internal URL.

  • EPSS 0.14%
  • Published 21.02.2024 20:15:46
  • Last modified 18.03.2025 17:53:45

Archer Platform 6.x before 6.14 P2 HF1 (6.14.0.2.1) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this by tricking a victim application user into supplying malicious JavaScript code to ...

  • EPSS 0.15%
  • Published 21.02.2024 20:15:46
  • Last modified 18.03.2025 17:39:03

Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated malicious user could potentially exploit this to gain access to API information that should only be accessible with extra privileg...

  • EPSS 0.21%
  • Published 12.12.2023 08:15:07
  • Last modified 21.11.2024 08:32:10

Archer Platform 6.x before 6.13 P2 (6.13.0.2) contains an authenticated HTML content injection vulnerability. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store...

  • EPSS 0.01%
  • Published 12.12.2023 08:15:07
  • Last modified 21.11.2024 08:32:09

Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authenticated malicious user in a multi-instance installation could potentially exploit this vulnerability by manipulating application ...