Vulnerabilities > Citadel > Low

DATE CVE VULNERABILITY TITLE RISK
2023-05-29 CVE-2021-37845 Unspecified vulnerability in Citadel Webcit 7.10/926
An issue was discovered in Citadel through webcit-932.
network
high complexity
citadel
3.7
2007-07-17 CVE-2007-3822 Cross-Site Scripting vulnerability in Citadel Webcit 7.10
Multiple cross-site scripting (XSS) vulnerabilities in Webcit before 7.11 allow remote attackers to inject arbitrary web script or HTML via (1) the who parameter to showuser; and other vectors involving (2) calendar mode, (3) bulletin board mode, (4) room names, and (5) uploaded file names.
network
high complexity
citadel
2.6
2004-04-12 CVE-2004-1933 Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages.
local
low complexity
citadel
2.1