Vulnerabilities (CVE)

Filtered by vendor Xpand-it Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-27172 1 Xpand-it 1 Write-back Manager 2024-01-02 N/A 9.1 CRITICAL
Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.
CVE-2019-19678 1 Xpand-it 1 Xray Test Mangaement 2019-12-11 3.5 LOW 5.4 MEDIUM
In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the generic field entry point via the Generic Test Definition field of a new Generic Test issue.
CVE-2019-19679 1 Xpand-it 1 Xray Test Mangaement 2019-12-11 3.5 LOW 5.4 MEDIUM
In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condition Summary entry point via the summary field of a Create Pre-Condition action for a new Test Issue.