Vulnerabilities (CVE)

Filtered by vendor Zend Subscribe
Filtered by product Zendto
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8984 1 Zend 1 Zendto 2020-03-27 5.0 MEDIUM 7.5 HIGH
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
CVE-2020-8985 1 Zend 1 Zendto 2020-03-27 6.8 MEDIUM 8.8 HIGH
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.