Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
webtareas project webtareas 2.4 vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2022-44953
webtareas 2.4p5 exists to contain a cross-site scripting (XSS) vulnerability in the component /linkedcontent/listfiles.php. This vulnerability allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "A...
Webtareas Project Webtareas 2.4
5.4
CVSSv3
CVE-2022-44956
webtareas 2.4p5 exists to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Webtareas Project Webtareas 2.4
8.8
CVSSv3
CVE-2021-41916
A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and previous versions allows a remote malicious user to create a new administrative profile and add a new user to the new profile. without the victim's knowledge, by enticing an authenticated admin us...
Webtareas Project Webtareas
7.5
CVSSv3
CVE-2021-41920
webTareas version 2.4 and previous versions allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an malicious user to access all t...
Webtareas Project Webtareas
5.4
CVSSv3
CVE-2021-41917
webTareas version 2.4 and previous versions allows an authenticated user to store arbitrary web script or HTML by creating or editing a client name in the clients section, due to incorrect sanitization of user-supplied data and achieve a Stored Cross-Site Scripting attack against...
Webtareas Project Webtareas
5.4
CVSSv3
CVE-2021-41918
webTareas version 2.4 and previous versions allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the platform users and administrators. The issue affects...
Webtareas Project Webtareas
8.8
CVSSv3
CVE-2021-41919
webTareas version 2.4 and previous versions allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is working by adding or replacing a personal profile picture. The affected endpoint is /includes/upload.php on the HTTP POST data....
Webtareas Project Webtareas
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
buffer overflow
type confusion
server-side request forgery
CVE-2024-38440
CVE-2024-27801
CVE-2024-5868
CVE-2024-0582
CVE-2024-37643
CVE-2024-3105
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2