Vulnerabilities (CVE)

Filtered by vendor Tiny Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-23562 1 Tiny 1 Plupload 2021-12-07 6.8 MEDIUM 8.8 HIGH
This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.
CVE-2019-10012 2 Jenzabar, Tiny 2 Internet Campus Solution, Moxiemanager 2019-09-20 6.0 MEDIUM 7.5 HIGH
Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a ZIP archive and using the MoxieManager (for .NET) plugin before 2.1.4 in the moxiemanager directory within the installation folder ICS\ICS.NET\ICSFileServer.