Vulnerabilities > Matrix42

DATE CVE VULNERABILITY TITLE RISK
2020-04-15 CVE-2019-19390 Cross-site Scripting vulnerability in Matrix42 Workspace Management 9.1.2.2765
The Search parameter of the Software Catalogue section of Matrix42 Workspace Management 9.1.2.2765 and below accepts unfiltered parameters that lead to multiple reflected XSS issues.
network
matrix42 CWE-79
3.5
2020-04-15 CVE-2019-19500 Cross-site Scripting vulnerability in Matrix42 Workspace Management 9.1.2.2765
Matrix42 Workspace Management 9.1.2.2765 and below allows stored XSS via unfiltered description parameters, as demonstrated by the comment field of a special order for individual software.
network
matrix42 CWE-79
3.5
2013-12-29 CVE-2013-2504 Cross-Site Scripting vulnerability in Matrix42 Service Store 5.3
Cross-site scripting (XSS) vulnerability in SPS/Portal/default.aspx in Service Desk in Matrix42 Service Store 5.3 SP3 (aka 5.33.946.0) allows remote attackers to inject arbitrary web script or HTML via the query string.
network
matrix42 CWE-79
4.3