ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-26770
+1 in the same advisory: …26771
TaskCafe 0.3.2 lacks validation in the Cookie value.

TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • taskcafe project taskcafe
CVE-2020-25400
Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to access sensitive data such as access token.

Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to access sensitive data such as access token.

NVD description · AI analysis pending
7.52%
  • taskcafe project taskcafe