ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-27704
Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.

Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.

NVD description · AI analysis pending
6.5<1%
  • appspace appspace
CVE-2021-27990
+1 in the same advisory: …27989
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed wi

Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities.

NVD description · AI analysis pending
7.5
group max
1%
  • appspace appspace
CVE-2021-27670
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

NVD description · AI analysis pending
9.861% PoC
  • appspace appspace
CVE-2021-27564
A stored XSS issue exists in Appspace 6.2.4.

A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups section of the network tab, it is stored as the group name. Whenever another member visits that group, this payload executes.

NVD description · AI analysis pending
5.4<1% PoC
  • appspace appspace
CVE-2020-5393
In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.

In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.

NVD description · AI analysis pending
6.1<1% PoC
  • appspace on-prem