Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
eng knowage vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2022-39295
Knowage is an open source suite for modern business analytics alternative over big data systems. KnowageLabs / Knowage-Server starting with the 6.x branch and prior to versions 7.4.22, 8.0.9, and 8.1.0 is vulnerable to cross-site scripting because the `XSSRequestWrapper::stripXSS...
Eng Knowage
5.4
CVSSv3
CVE-2021-30056
Knowage Suite prior to 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publish via the 'EXEC_FROM' parameter that can lead to data leakage.
Eng Knowage
6.1
CVSSv3
CVE-2021-30058
Knowage Suite prior to 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in '/knowagecockpitengine/api/1.0/pages/execute' via the 'SBI_HOST' parameter.
Eng Knowage
6.5
CVSSv3
CVE-2023-36819
Knowage is the professional open source suite for modern business analytics over traditional sources and big data systems. The endpoint `_/knowage/restful-services/dossier/importTemplateFile_` allows authenticated users to download template hosted on the server. However, starting...
Eng Knowage
9.8
CVSSv3
CVE-2019-13188
In Knowage up to and including 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
Eng Knowage
6.1
CVSSv3
CVE-2019-13189
In Knowage up to and including 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.
Eng Knowage
5.3
CVSSv3
CVE-2019-13190
In Knowage up to and including 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.
Eng Knowage
8.8
CVSSv3
CVE-2019-13348
In Knowage up to and including 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.
Eng Knowage
6.5
CVSSv3
CVE-2023-37472
Knowage is an open source suite for business analytics. The application often use user supplied data to create HQL queries without prior sanitization. An attacker can create specially crafted HQL queries that will break subsequent SQL queries generated by the Hibernate engine. Th...
Eng Knowage
8.8
CVSSv3
CVE-2023-38702
Knowage is an open source analytics and business intelligence suite. Starting in the 6.x.x branch and prior to version 8.1.8, the endpoint `/knowage/restful-services/dossier/importTemplateFile` allows authenticated users to upload `template file` on the server, but does not need ...
Eng Knowage
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »