Vulnerabilities (CVE)

Filtered by CWE-276
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-16106 1 Humanica 1 Humatrix 2019-09-11 5.0 MEDIUM 7.5 HIGH
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.
CVE-2019-16183 1 Limesurvey 1 Limesurvey 2019-09-10 4.0 MEDIUM 2.7 LOW
In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions.
CVE-2019-16185 1 Limesurvey 1 Limesurvey 2019-09-10 6.5 MEDIUM 7.2 HIGH
In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
CVE-2019-16186 1 Limesurvey 1 Limesurvey 2019-09-10 6.5 MEDIUM 7.2 HIGH
In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.