CVE-2021-3758
- EPSS 0.8%
- Veröffentlicht 02.09.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:21
bookstack is vulnerable to Server-Side Request Forgery (SSRF)
CVE-2020-26260
- EPSS 0.83%
- Veröffentlicht 09.12.2020 17:15:30
- Zuletzt bearbeitet 21.11.2024 05:19:41
BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit a page could set certain image URL's to manipulate functionality in the exporting system, which woul...
CVE-2020-26211
- EPSS 1.1%
- Veröffentlicht 03.11.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:32
In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current page, when clicked or submitted. Ad...
CVE-2020-26210
- EPSS 1.17%
- Veröffentlicht 03.11.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:19:31
In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code when clicked by a viewer of the page. Dangerous content may remain in the database after this update. ...
CVE-2020-11055
- EPSS 0.78%
- Veröffentlicht 07.05.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:41
In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A user with permission to create comments could POST HTML directly to the system to be saved in a comment, which would then be execu...
- EPSS 1.95%
- Veröffentlicht 09.03.2020 16:15:15
- Zuletzt bearbeitet 21.11.2024 05:33:46
BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to execute code on the host system remotely. They would then have the permissions of the PHP process. This ...
CVE-2017-1000462
- EPSS 0.76%
- Veröffentlicht 03.01.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:47
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.