Accellion

Kiteworks

50 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.24%
  • Veröffentlicht 30.09.2026 20:09:21
  • Zuletzt bearbeitet 07.10.2026 15:02:08

Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of tha...

Medienbericht
  • EPSS 0.3%
  • Veröffentlicht 30.09.2026 20:09:08
  • Zuletzt bearbeitet 07.10.2026 15:02:06

A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. Thi...

  • EPSS 1.09%
  • Veröffentlicht 30.09.2026 20:07:35
  • Zuletzt bearbeitet 07.10.2026 13:22:54

Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could caus...

  • EPSS 0.64%
  • Veröffentlicht 30.09.2026 20:07:29
  • Zuletzt bearbeitet 07.10.2026 13:24:18

Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary lo...

  • EPSS 0.34%
  • Veröffentlicht 30.09.2026 20:06:49
  • Zuletzt bearbeitet 07.10.2026 13:22:21

Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permi...

  • EPSS 0.21%
  • Veröffentlicht 30.09.2026 20:06:03
  • Zuletzt bearbeitet 07.10.2026 13:21:51

Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared...

  • EPSS 0.2%
  • Veröffentlicht 30.09.2026 20:05:32
  • Zuletzt bearbeitet 07.10.2026 13:15:27

Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application ...

  • EPSS 0.33%
  • Veröffentlicht 30.09.2026 20:05:28
  • Zuletzt bearbeitet 07.10.2026 13:23:42

Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database an...

  • EPSS 0.67%
  • Veröffentlicht 01.06.2026 22:00:24
  • Zuletzt bearbeitet 22.07.2026 18:10:00

Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be exploited by an authenticated attacker with the FormBuilder role to retrieve information on or modify othe...

  • EPSS 0.14%
  • Veröffentlicht 01.06.2026 21:52:53
  • Zuletzt bearbeitet 22.07.2026 19:10:00

Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to access metadata of resources belonging to other users due to in...