Vulnerabilities
13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-45180 | SquaredUp DS for SCOM 6.2.1.11104 allows XSS. SquaredUp DS for SCOM 6.2.1.11104 allows XSS. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2022-46785 | SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2). SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2). NVD description · AI analysis pending | 6.1 group max | <1% |
| — | ||
| CVE-2021-40096 | A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via modification of the authorisationUrl in some integration configurations. NVD description · AI analysis pending | 5.4 group max | <1% |
| — | ||
| CVE-2021-40091 | An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654. An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2020-9388 | CSRF protection was not present in SquaredUp before version 4.6.0. CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard. NVD description · AI analysis pending | 6.5 group max | <1% |
| — |