Vulnerabilities
7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-48708 | Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php und Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php under action = adduser/edituser. NVD description · AI analysis pending | 5.4 group max | <1% | PoC |
| — | |
| CVE-2021-3298 | Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter. NVD description · AI analysis pending | 5.4 | 2% | PoC |
| — | |
| CVE-2020-13655 | An issue was discovered in Collabtive 3.0 and later. An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are reflected. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2019-8935 | Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter. Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — |