ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-48708
+3 in the same advisory: …48707 …48706 …46240
Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php und

Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php under action = adduser/edituser.

NVD description · AI analysis pending
5.4
group max
<1% PoC
  • o-dyn collabtive
CVE-2021-3298
Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit

Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.

NVD description · AI analysis pending
5.42% PoC
  • o-dyn collabtive
CVE-2020-13655
An issue was discovered in Collabtive 3.0 and later.

An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are reflected.

NVD description · AI analysis pending
6.1<1% PoC
  • o-dyn collabtive
CVE-2019-8935
Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.

Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.

NVD description · AI analysis pending
5.4<1% PoC
  • o-dyn collabtive