|
208271
|
8.7 |
HIGH
Network
|
hedgedoc
|
hedgedoc
|
HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an attacker can inject arbitrary `script` tags in HedgeDoc notes using mermaid diagrams. Our co…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26287
|
2024-11-21 14:19 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208272
|
7.5 |
HIGH
Network
|
hedgedoc
|
hedgedoc
|
HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an unauthenticated attacker can upload arbitrary files to the upload storage backend including …
|
-
|
CVE-2020-26286
|
2024-11-21 14:19 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208273
|
9.6 |
CRITICAL
Network
|
linuxfoundation
|
dex
|
Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users leveraging the SAML connector. The vulnerabilitie…
|
-
|
CVE-2020-26290
|
2024-11-21 14:19 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208274
|
7.5 |
HIGH
Network
|
date-and-time_project
|
date-and-time
|
date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of s…
|
-
|
CVE-2020-26289
|
2024-11-21 14:19 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208275
|
5.4 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. There is Stored XSS via a Tags element in a TIcket.
|
CWE-79
Cross-site Scripting
|
CVE-2020-26035
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208276
|
4.3 |
MEDIUM
Network
|
zammad
|
zammad
|
An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The …
|
NVD-CWE-noinfo
|
CVE-2020-26034
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208277
|
5.4 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.
|
CWE-352
Origin Validation Error
|
CVE-2020-26033
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208278
|
7.5 |
HIGH
Network
|
zammad
|
zammad
|
An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the result of a test request to the User. An attacker can u…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-26032
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208279
|
4.3 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. The global-search feature leaks Knowledge Base drafts to Knowledge Base readers (who are authenticated but have insufficient permissions).
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-26031
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208280
|
9.8 |
CRITICAL
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticate…
|
CWE-287
Improper Authentication
|
CVE-2020-26030
|
2024-11-21 14:19 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|