Vulnerabilities > Clickstudios > Low

DATE CVE VULNERABILITY TITLE RISK
2023-10-31 CVE-2023-43295 Cross-Site Request Forgery (CSRF) vulnerability in Clickstudios Passwordstate 9.7
Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a local attacker to execute arbitrary code via a crafted request.
network
low complexity
clickstudios CWE-352
3.5
2020-10-29 CVE-2020-27747 Insufficiently Protected Credentials vulnerability in Clickstudios Passwordstate 8.9
An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built-in generator (4 digits), a remote attacker has the opportunity to conduct a brute force attack on this PIN code.
local
low complexity
clickstudios CWE-522
2.1
2018-08-01 CVE-2018-14776 Cross-site Scripting vulnerability in Clickstudios Passwordstate 8.3
Click Studios Passwordstate before 8.3 Build 8397 allows XSS by authenticated users via an uploaded HTML document.
3.5