Vulnerabilities (CVE)

Filtered by vendor Novell Subscribe
Filtered by product Filr
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-1609 1 Novell 1 Filr 2017-09-03 3.5 LOW 5.4 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allow remote authenticated users to inject arbitrary web script or HTML via crafted input, as demonstrated by a crafted attribute of an IMG element in the phone field of a user profile.
CVE-2015-5968 1 Novell 1 Filr 2016-03-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Novell Filr 1.2 before Hot Patch 4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.