Vulnerabilities (CVE)

Filtered by vendor Webtareas Project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-36608 1 Webtareas Project 1 Webtareas 2022-06-27 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php.
CVE-2021-36609 1 Webtareas Project 1 Webtareas 2022-06-27 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder.php.
CVE-2021-41918 1 Webtareas Project 1 Webtareas 2021-10-15 3.5 LOW 5.4 MEDIUM
webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the platform users and administrators. The issue affects every endpoint on the application because it is related on how each URL is echoed back on every response page.
CVE-2021-41917 1 Webtareas Project 1 Webtareas 2021-10-15 3.5 LOW 5.4 MEDIUM
webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or editing a client name in the clients section, due to incorrect sanitization of user-supplied data and achieve a Stored Cross-Site Scripting attack against the platform users and administrators. The affected endpoint is /clients/editclient.php, on the HTTP POST cn parameter.
CVE-2020-23069 1 Webtareas Project 1 Webtareas 2021-08-24 4.0 MEDIUM 6.5 MEDIUM
Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files.
CVE-2020-25735 1 Webtareas Project 1 Webtareas 2020-09-24 4.3 MEDIUM 6.1 MEDIUM
webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/claim_type.php, projects/editproject.php, and general/newnotifications.php.
CVE-2020-25734 1 Webtareas Project 1 Webtareas 2020-09-24 5.0 MEDIUM 5.3 MEDIUM
webTareas through 2.1 allows files/Default/ Directory Listing.
CVE-2020-23660 1 Webtareas Project 1 Webtareas 2020-08-28 3.5 LOW 5.4 MEDIUM
webTareas v2.1 is affected by Cross Site Scripting (XSS) on "Search."
CVE-2020-14973 1 Webtareas Project 1 Webtareas 2020-06-25 4.3 MEDIUM 6.1 MEDIUM
The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS) vulnerability via the query string.