|
215701
|
6.3 |
MEDIUM
Network
|
redhat
|
cloudforms_management_engine
|
Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula …
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-10780
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215702
|
8.3 |
HIGH
Network
|
redhat
|
cloudforms
|
Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricted only to EVM-Super-administrator group, leads to,…
|
NVD-CWE-noinfo
|
CVE-2020-10783
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215703
|
6.5 |
MEDIUM
Network
|
redhat
|
cloudforms
|
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right cri…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-10779
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215704
|
6.0 |
MEDIUM
Network
|
redhat
|
cloudforms
|
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This busines…
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2020-10778
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215705
|
5.4 |
MEDIUM
Network
|
redhat
|
cloudforms
|
A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using Clou…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10777
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215706
|
4.8 |
MEDIUM
Network
|
gambio
|
gambio_gx
|
Gambio GX before 4.0.1.0 allows XSS in admin/coupon_admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10985
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215707
|
8.8 |
HIGH
Network
|
gambio
|
gambio_gx
|
Gambio GX before 4.0.1.0 allows admin/admin.php CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-10984
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215708
|
4.9 |
MEDIUM
Network
|
gambio
|
gambio_gx
|
Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php.
|
CWE-89
SQL Injection
|
CVE-2020-10983
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215709
|
4.9 |
MEDIUM
Network
|
gambio
|
gambio_gx
|
Gambio GX before 4.0.1.0 allows SQL Injection in admin/gv_mail.php.
|
CWE-89
SQL Injection
|
CVE-2020-10982
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215710
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
r6700_firmware
|
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit …
|
NVD-CWE-Other
|
CVE-2020-10930
|
2024-11-21 13:56 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|