Vulnerabilities (CVE)

Filtered by vendor Openasset Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-28861 1 Openasset 1 Digital Asset Management 2020-12-15 5.0 MEDIUM 5.3 MEDIUM
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.
CVE-2020-28859 1 Openasset 1 Digital Asset Management 2020-12-15 4.3 MEDIUM 6.1 MEDIUM
OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for reflected cross-site scripting attacks.
CVE-2020-28857 1 Openasset 1 Digital Asset Management 2020-12-15 4.3 MEDIUM 6.1 MEDIUM
OpenAsset Digital Asset Management (DAM) through 12.0.19, does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for stored cross-site scripting attacks.