Vulnerabilities > Citadel > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-04 | CVE-2023-44272 | Cross-site Scripting vulnerability in Citadel A cross-site scripting vulnerability exists in Citadel versions prior to 994. | 5.4 |
2023-05-29 | CVE-2020-29547 | Command Injection vulnerability in Citadel Webcit An issue was discovered in Citadel through webcit-926. | 5.9 |
2020-10-28 | CVE-2020-27742 | Authorization Bypass Through User-Controlled Key vulnerability in Citadel Webcit An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move template. | 6.5 |
2020-10-28 | CVE-2020-27741 | Cross-site Scripting vulnerability in Citadel Webcit Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbitrary web script or HTML via multiple pages and parameters. | 6.1 |
2020-10-28 | CVE-2020-27740 | Unspecified vulnerability in Citadel Webcit Citadel WebCit through 926 allows unauthenticated remote attackers to enumerate valid users within the platform. | 5.3 |