Vulnerabilities > Citadel > Webcit
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-29 | CVE-2020-29547 | Command Injection vulnerability in Citadel Webcit 7.10/926 An issue was discovered in Citadel through webcit-926. | 5.9 |
2023-05-29 | CVE-2021-37845 | Unspecified vulnerability in Citadel Webcit 7.10/926 An issue was discovered in Citadel through webcit-932. | 3.7 |
2020-10-28 | CVE-2020-27742 | Authorization Bypass Through User-Controlled Key vulnerability in Citadel Webcit 7.10/926 An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move template. | 4.0 |
2020-10-28 | CVE-2020-27741 | Cross-site Scripting vulnerability in Citadel Webcit 7.10/926 Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbitrary web script or HTML via multiple pages and parameters. | 4.3 |
2020-10-28 | CVE-2020-27740 | Unspecified vulnerability in Citadel Webcit 7.10/926 Citadel WebCit through 926 allows unauthenticated remote attackers to enumerate valid users within the platform. | 5.0 |
2020-10-28 | CVE-2020-27739 | Insufficient Session Expiration vulnerability in Citadel Webcit 7.10/926 A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in users' sessions. | 7.5 |
2009-03-26 | CVE-2009-0364 | USE of Externally-Controlled Format String vulnerability in Citadel Webcit Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows remote attackers to execute arbitrary code via unspecified vectors. | 7.5 |
2007-07-17 | CVE-2007-3822 | Cross-Site Scripting vulnerability in Citadel Webcit 7.10 Multiple cross-site scripting (XSS) vulnerabilities in Webcit before 7.11 allow remote attackers to inject arbitrary web script or HTML via (1) the who parameter to showuser; and other vectors involving (2) calendar mode, (3) bulletin board mode, (4) room names, and (5) uploaded file names. | 2.6 |
2007-07-17 | CVE-2007-3821 | Input Validation vulnerability in Citadel Webcit 7.10 Cross-site request forgery (CSRF) vulnerability in Webcit before 7.11 allows remote attackers to modify configurations and perform other actions as arbitrary users via unspecified vectors. | 7.5 |