Vulnerabilities > Devolutions > Devolutions Server

DATE CVE VULNERABILITY TITLE RISK
2023-03-01 CVE-2023-0952 Incorrect Authorization vulnerability in Devolutions Server
Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization.
network
low complexity
devolutions CWE-863
6.5
2023-03-01 CVE-2023-0953 SQL Injection vulnerability in Devolutions Server
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.
network
low complexity
devolutions CWE-89
8.8
2023-02-12 CVE-2023-0661 Unspecified vulnerability in Devolutions Server
Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.
network
low complexity
devolutions
6.5
2022-11-01 CVE-2022-3781 Insufficiently Protected Credentials vulnerability in Devolutions Remote Desktop Manager
Dashlane password and Keepass Server password in My Account Settings  are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This issue affects : Remote Desktop Manager 2022.2.26 and prior versions. Devolutions Server 2022.3.1 and prior versions.
network
low complexity
devolutions CWE-522
6.5
2022-07-07 CVE-2022-33996 Incorrect Default Permissions vulnerability in Devolutions Server
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that previous user.
network
low complexity
devolutions CWE-276
6.5
2022-07-06 CVE-2022-2316 Cross-site Scripting vulnerability in Devolutions Server
HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the rendering of the page or redirect a user to another site.
3.5
2021-07-12 CVE-2021-36382 Insufficiently Protected Credentials vulnerability in Devolutions Server
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
4.3
2021-04-01 CVE-2021-23925 Cross-site Scripting vulnerability in Devolutions Server
An issue was discovered in Devolutions Server before 2020.3.
4.3
2021-04-01 CVE-2021-23924 Information Exposure Through Log Files vulnerability in Devolutions Server
An issue was discovered in Devolutions Server before 2020.3.
network
low complexity
devolutions CWE-532
5.0
2021-04-01 CVE-2021-23923 Improper Authentication vulnerability in Devolutions Server
An issue was discovered in Devolutions Server before 2020.3.
4.9