Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
eng knowage 6.1.1 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2018-12355
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.
Eng Knowage 6.1.1
5
CVSSv2
CVE-2019-13188
In Knowage up to and including 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
Eng Knowage
4.3
CVSSv2
CVE-2019-13189
In Knowage up to and including 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.
Eng Knowage
5
CVSSv2
CVE-2019-13190
In Knowage up to and including 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.
Eng Knowage
4
CVSSv2
CVE-2019-13348
In Knowage up to and including 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.
Eng Knowage
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
firewall
CVE-2024-35649
stored XSS
CVE-2022-28654
CVE-2020-35153
CVE-2024-27348
CVE-2022-28652
local users
CVE-2017-3506
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started