Vulnerabilities > Citadel > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-29 | CVE-2021-37845 | Unspecified vulnerability in Citadel Webcit 7.10/926 An issue was discovered in Citadel through webcit-932. | 3.7 |
2007-07-17 | CVE-2007-3822 | Cross-Site Scripting vulnerability in Citadel Webcit 7.10 Multiple cross-site scripting (XSS) vulnerabilities in Webcit before 7.11 allow remote attackers to inject arbitrary web script or HTML via (1) the who parameter to showuser; and other vectors involving (2) calendar mode, (3) bulletin board mode, (4) room names, and (5) uploaded file names. | 2.6 |
2004-04-12 | CVE-2004-1933 | Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages. | 2.1 |