Vulnerabilities > Boolebox
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-06-24 | CVE-2020-13247 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Boolebox BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area. | 7.3 |
2020-06-24 | CVE-2020-13248 | Cross-site Scripting vulnerability in Boolebox BooleBox Secure File Sharing Utility before 4.2.3.0 allows stored XSS via a crafted avatar field within My Account JSON data to Account.aspx. | 5.4 |