|
247681
|
5.4 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is XSS in invitation mail received from a different user, who can modify the HTML in that mail before sending it.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10213
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247682
|
5.4 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creation of folders within another account via a modified device value.
|
CWE-863
Incorrect Authorization
|
CVE-2018-10212
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247683
|
5.3 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization when listing the history of another user via a modified "vaultize_session_id" value in a cookie.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2018-10211
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247684
|
5.3 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. Enumeration of users is possible through the password-reset feature.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2018-10210
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247685
|
5.4 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS on the file or folder download pop-up via a crafted file or folder name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10209
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247686
|
6.1 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is anonymous reflected XSS on the error page via a /share/error?message= URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10208
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247687
|
5.3 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. An attacker can exploit Missing Authorization on the FlexPaperViewer SWF reader, and export files that should have been restricte…
|
CWE-862
Missing Authorization
|
CVE-2018-10207
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247688
|
5.4 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS via the optional message field of a file request.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10206
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247689
|
7.5 |
HIGH
Network
|
smartmesh
|
smartmesh
|
An integer overflow in the transferProxy function of a smart contract implementation for SmartMesh (aka SMT), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digit…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-10376
|
2024-11-21 12:41 |
2018-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247690
|
9.8 |
CRITICAL
Network
|
dedecms
|
dedecms
|
A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to upload and execute arbitrary PHP code via the /dede/archives_do.…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-10375
|
2024-11-21 12:41 |
2018-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|