Skip to main content

Vendor archive

o-dyn CVEs

Beta · best-effort

16 CVEs tagged to vendor o-dyn1 Critical, 2 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2024-48708

Published Oct 22, 2024

Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php under action = adduser…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48707

Published Oct 22, 2024

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48706

Published Oct 22, 2024

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46240

Published Oct 22, 2024

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters under action=addcust within admin.php file.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3298

Published Jan 29, 2021

Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13655

Published Aug 31, 2020

An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a projec…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8935

Published Feb 19, 2019

Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3247

Published May 15, 2014

Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3246

Published May 13, 2014

SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via the folder parameter in a fileview_list action to manageajax.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6872

Published Jan 21, 2014

SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a project…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5285

Published Nov 26, 2012

Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrators for requests that add admin…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5284

Published Nov 26, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) User parameter in the edit user p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2670

Published Jun 17, 2012

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4269

Published Nov 17, 2010

SQL injection vulnerability in managechat.php in Collabtive 0.65 allows remote attackers to execute arbitrary SQL commands via the chatstart[USERTOID] cookie in a pull action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1