|
219451
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Control.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-20143
|
2024-11-21 13:38 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219452
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.3 through 12.6.1. It allows Denial of Service.
|
NVD-CWE-noinfo
|
CVE-2019-20142
|
2024-11-21 13:38 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219453
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-20148
|
2024-11-21 13:38 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219454
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-20147
|
2024-11-21 13:38 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219455
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncontrolled Resource Consumption.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-20146
|
2024-11-21 13:38 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219456
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.4 through 12.6.1. It has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-20145
|
2024-11-21 13:38 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219457
|
6.1 |
MEDIUM
Network
|
cththemes
|
citybook easybook townhub
|
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20212
|
2024-11-21 13:38 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219458
|
6.1 |
MEDIUM
Network
|
cththemes
|
citybook easybook townhub
|
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address,…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20211
|
2024-11-21 13:38 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219459
|
6.1 |
MEDIUM
Network
|
cththemes
|
citybook easybook townhub
|
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20210
|
2024-11-21 13:38 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219460
|
7.5 |
HIGH
Network
|
cththemes
|
citybook easybook townhub
|
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/p…
|
CWE-79 CWE-639
Cross-site Scripting Authorization Bypass Through User-Controlled Key
|
CVE-2019-20209
|
2024-11-21 13:38 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|