Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-11-06 | CVE-2017-15039 | Cross-site Scripting vulnerability in Zurmo CRM 3.2.1.57987Acc3018 Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting. | 4.8 |
2017-11-03 | CVE-2017-14359 | Cross-site Scripting vulnerability in HP Performance Center 12.20 A potential security vulnerability has been identified in HPE Performance Center versions 12.20. | 5.4 |
2017-11-03 | CVE-2017-1000149 | Cross-site Scripting vulnerability in Mahara Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open()) | 5.4 |
2017-11-03 | CVE-2017-1000146 | Cross-site Scripting vulnerability in Mahara Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages. | 5.4 |
2017-11-03 | CVE-2017-1000144 | Cross-site Scripting vulnerability in Mahara Mahara 1.9 before 1.9.6 and 1.10 before 1.10.4 and 15.04 before 15.04.1 are vulnerable to a site admin or institution admin being able to place HTML and Javascript into an institution display name, which will be displayed to other users unescaped on some Mahara system pages. | 4.8 |
2017-11-03 | CVE-2017-1000140 | Cross-site Scripting vulnerability in Mahara Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .xml file that can have its code executed when user tries to download the file. | 5.4 |
2017-11-03 | CVE-2017-1000138 | Cross-site Scripting vulnerability in Mahara 1.10/15.04 Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when dragging/dropping files into a collection if the file has Javascript code in its title. | 5.4 |
2017-11-03 | CVE-2017-1000137 | Cross-site Scripting vulnerability in Mahara 1.10/15.04 Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when adding a text block to a page via the keyboard (rather than drag and drop). | 5.4 |
2017-11-03 | CVE-2017-1000132 | Cross-site Scripting vulnerability in Mahara Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .swf files that can have its code executed when a user tries to download the file. | 4.8 |
2017-11-02 | CVE-2017-12294 | Cross-site Scripting vulnerability in Cisco Webex Meetings Server A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected system. | 5.4 |