CVE-2024-23737
- EPSS 0.19%
- Veröffentlicht 01.07.2024 22:15:02
- Zuletzt bearbeitet 18.03.2025 15:15:47
Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.
CVE-2024-23734
- EPSS 0.17%
- Veröffentlicht 10.04.2024 16:15:09
- Zuletzt bearbeitet 17.06.2025 17:53:29
Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME certificate or PGP keys for arbitrary users via crafted link.
CVE-2024-23735
- EPSS 0.64%
- Veröffentlicht 10.04.2024 16:15:09
- Zuletzt bearbeitet 17.06.2025 17:44:56
Cross Site Scripting (XSS) vulnerability in in the S/MIME certificate upload functionality of the User Profile pages in savignano S/Notify before 4.0.0 for Confluence allows attackers to manipulate user data via specially crafted certificate.
CVE-2023-50932
- EPSS 0.05%
- Veröffentlicht 09.01.2024 07:15:10
- Zuletzt bearbeitet 06.01.2026 19:37:25
An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clic...
CVE-2023-50931
- EPSS 0.05%
- Veröffentlicht 09.01.2024 07:15:09
- Zuletzt bearbeitet 06.01.2026 19:37:56
An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator click...
CVE-2023-50930
- EPSS 0.05%
- Veröffentlicht 09.01.2024 07:15:07
- Zuletzt bearbeitet 14.05.2025 20:15:20
An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a...