Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-27704 | Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page. Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2021-27990 +1 in the same advisory: …27989 | Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed wi Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities. NVD description · AI analysis pending | 7.5 group max | 1% |
| — | ||
| CVE-2021-27670 | Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter. Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter. NVD description · AI analysis pending | 9.8 | 61% | PoC |
| — | |
| CVE-2021-27564 | A stored XSS issue exists in Appspace 6.2.4. A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups section of the network tab, it is stored as the group name. Whenever another member visits that group, this payload executes. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2020-5393 | In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS. In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — |