Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
webtareas project webtareas vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2021-43481
An SQL Injection vulnerability exists in Webtareas 2.4p3 and previous versions via the $uq HTTP POST parameter in editapprovalstage.php.
Webtareas Project Webtareas 2.4
Webtareas Project Webtareas
605
VMScore
CVE-2021-41916
A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and previous versions allows a remote malicious user to create a new administrative profile and add a new user to the new profile. without the victim's knowledge, by enticing an authenticated admin us...
Webtareas Project Webtareas
578
VMScore
CVE-2021-41919
webTareas version 2.4 and previous versions allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is working by adding or replacing a personal profile picture. The affected endpoint is /includes/upload.php on the HTTP POST data....
Webtareas Project Webtareas
445
VMScore
CVE-2021-41920
webTareas version 2.4 and previous versions allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an malicious user to access all t...
Webtareas Project Webtareas
445
VMScore
CVE-2020-25733
webTareas up to and including 2.1 allows upload of the dangerous .exe and .shtml file types.
Webtareas Project Webtareas
445
VMScore
CVE-2020-25734
webTareas up to and including 2.1 allows files/Default/ Directory Listing.
Webtareas Project Webtareas
383
VMScore
CVE-2020-25735
webTareas up to and including 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/claim_type.php, projects/editproject.php, and general/newnotifications....
Webtareas Project Webtareas
383
VMScore
CVE-2020-14973
The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS) vulnerability via the query string.
Webtareas Project Webtareas 2.0
356
VMScore
CVE-2020-23069
Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files.
Webtareas Project Webtareas 2.0
312
VMScore
CVE-2021-36608
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php.
Webtareas Project Webtareas 2.2
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »