CVE-2021-26723
Published Feb 6, 2021Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.
Vendor archive
5 CVEs tagged to vendor jenzabar — 2 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.
Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.
Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch 8 has session cookies that are a deterministic function of…
Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a ZIP archive and using the MoxieManager…
ICS/StaticPages/AddTestUsers.aspx in Jenzabar JICS (aka Internet Campus Solution) before 2019-02-06 allows remote attackers to create an arbitrary number of accounts with a passwo…
Cross-site scripting (XSS) vulnerability in Jenzabar v8.2.1 through 9.2.0 allows remote attackers to inject arbitrary web script or HTML via the query parameter (aka the Search Fi…