Savignano

S-notify

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 01.07.2024 22:15:02
  • Zuletzt bearbeitet 18.03.2025 15:15:47

Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.

  • EPSS 0.17%
  • Veröffentlicht 10.04.2024 16:15:09
  • Zuletzt bearbeitet 17.06.2025 17:53:29

Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME certificate or PGP keys for arbitrary users via crafted link.

  • EPSS 0.64%
  • Veröffentlicht 10.04.2024 16:15:09
  • Zuletzt bearbeitet 17.06.2025 17:44:56

Cross Site Scripting (XSS) vulnerability in in the S/MIME certificate upload functionality of the User Profile pages in savignano S/Notify before 4.0.0 for Confluence allows attackers to manipulate user data via specially crafted certificate.

  • EPSS 0.05%
  • Veröffentlicht 09.01.2024 07:15:10
  • Zuletzt bearbeitet 06.01.2026 19:37:25

An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clic...

  • EPSS 0.05%
  • Veröffentlicht 09.01.2024 07:15:09
  • Zuletzt bearbeitet 06.01.2026 19:37:56

An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator click...

  • EPSS 0.05%
  • Veröffentlicht 09.01.2024 07:15:07
  • Zuletzt bearbeitet 14.05.2025 20:15:20

An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a...