CVE-2025-56313
- EPSS 0.09%
- Veröffentlicht 30.10.2025 00:00:00
- Zuletzt bearbeitet 04.11.2025 15:41:56
A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the /publix/run endpoint of JATOS 3.7.1 through 3.9.6 (inclusive). This allows remote attackers to execute arbitrary JavaScript in a user's web browser by including a malicious pa...
CVE-2024-51379
- EPSS 0.1%
- Veröffentlicht 05.11.2024 19:15:07
- Zuletzt bearbeitet 24.06.2025 13:28:19
Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject JavaScript into the description field. This allows for the execution ...
CVE-2024-51380
- EPSS 0.1%
- Veröffentlicht 05.11.2024 19:15:07
- Zuletzt bearbeitet 24.06.2025 13:22:14
Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows an attacker to inject malicious JavaScript into the properties section of a study, specifically within the UUID field. When an ad...
CVE-2024-51381
- EPSS 0.07%
- Veröffentlicht 05.11.2024 19:15:07
- Zuletzt bearbeitet 24.06.2025 13:20:52
Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security...
CVE-2024-51382
- EPSS 0.07%
- Veröffentlicht 05.11.2024 19:15:07
- Zuletzt bearbeitet 24.06.2025 13:13:53
Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical security flaw can result in unauthorized access to the platform, enabling attackers to hijack admin accounts and c...
CVE-2022-4878
- EPSS 0.28%
- Veröffentlicht 06.01.2023 10:15:10
- Zuletzt bearbeitet 21.11.2024 07:36:07
A vulnerability classified as critical has been found in JATOS. Affected is the function ZipUtil of the file modules/common/app/utils/common/ZipUtil.java of the component ZIP Handler. The manipulation leads to path traversal. Upgrading to version 3.7...