Vulnerabilities > Netcommons

DATE CVE VULNERABILITY TITLE RISK
2019-12-26 CVE-2019-6018 Cross-site Scripting vulnerability in Netcommons
Cross-site scripting vulnerability in NetCommons 3.2.2 and earlier (NetCommons3.x) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
netcommons CWE-79
6.1
2016-06-19 CVE-2016-4813 Improper Access Control vulnerability in Netcommons 2.4.2.1
NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.
network
low complexity
netcommons CWE-284
8.8