Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2017-11-06 CVE-2017-15039 Cross-site Scripting vulnerability in Zurmo CRM 3.2.1.57987Acc3018
Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.
network
low complexity
zurmo CWE-79
4.8
2017-11-03 CVE-2017-14359 Cross-site Scripting vulnerability in HP Performance Center 12.20
A potential security vulnerability has been identified in HPE Performance Center versions 12.20.
network
low complexity
hp CWE-79
5.4
2017-11-03 CVE-2017-1000149 Cross-site Scripting vulnerability in Mahara
Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open())
network
low complexity
mahara CWE-79
5.4
2017-11-03 CVE-2017-1000146 Cross-site Scripting vulnerability in Mahara
Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages.
network
low complexity
mahara CWE-79
5.4
2017-11-03 CVE-2017-1000144 Cross-site Scripting vulnerability in Mahara
Mahara 1.9 before 1.9.6 and 1.10 before 1.10.4 and 15.04 before 15.04.1 are vulnerable to a site admin or institution admin being able to place HTML and Javascript into an institution display name, which will be displayed to other users unescaped on some Mahara system pages.
network
low complexity
mahara CWE-79
4.8
2017-11-03 CVE-2017-1000140 Cross-site Scripting vulnerability in Mahara
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .xml file that can have its code executed when user tries to download the file.
network
low complexity
mahara CWE-79
5.4
2017-11-03 CVE-2017-1000138 Cross-site Scripting vulnerability in Mahara 1.10/15.04
Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when dragging/dropping files into a collection if the file has Javascript code in its title.
network
low complexity
mahara CWE-79
5.4
2017-11-03 CVE-2017-1000137 Cross-site Scripting vulnerability in Mahara 1.10/15.04
Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when adding a text block to a page via the keyboard (rather than drag and drop).
network
low complexity
mahara CWE-79
5.4
2017-11-03 CVE-2017-1000132 Cross-site Scripting vulnerability in Mahara
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .swf files that can have its code executed when a user tries to download the file.
network
low complexity
mahara CWE-79
4.8
2017-11-02 CVE-2017-12294 Cross-site Scripting vulnerability in Cisco Webex Meetings Server
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected system.
network
low complexity
cisco CWE-79
5.4