Vulnerabilities > Greenbone > Greenbone Security Assistant > 7.0.1

DATE CVE VULNERABILITY TITLE RISK
2021-06-21 CVE-2018-25016 Injection vulnerability in Greenbone OS and Greenbone Security Assistant
Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
network
low complexity
greenbone CWE-74
critical
9.8
2021-06-21 CVE-2019-25047 Cross-site Scripting vulnerability in Greenbone Security Assistant
Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling in gsad.
network
low complexity
greenbone CWE-79
6.1