Vulnerabilities > Citadel > Webcit

DATE CVE VULNERABILITY TITLE RISK
2023-05-29 CVE-2020-29547 Command Injection vulnerability in Citadel Webcit
An issue was discovered in Citadel through webcit-926.
network
high complexity
citadel CWE-77
5.9
2023-05-29 CVE-2021-37845 Unspecified vulnerability in Citadel Webcit
An issue was discovered in Citadel through webcit-932.
network
high complexity
citadel
3.7
2020-10-28 CVE-2020-27742 Authorization Bypass Through User-Controlled Key vulnerability in Citadel Webcit
An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move template.
network
low complexity
citadel CWE-639
6.5
2020-10-28 CVE-2020-27741 Cross-site Scripting vulnerability in Citadel Webcit
Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbitrary web script or HTML via multiple pages and parameters.
network
low complexity
citadel CWE-79
6.1
2020-10-28 CVE-2020-27740 Unspecified vulnerability in Citadel Webcit
Citadel WebCit through 926 allows unauthenticated remote attackers to enumerate valid users within the platform.
network
low complexity
citadel
5.3
2020-10-28 CVE-2020-27739 Insufficient Session Expiration vulnerability in Citadel Webcit
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in users' sessions.
network
low complexity
citadel CWE-613
critical
9.8