Vulnerabilities > Open Audit

DATE CVE VULNERABILITY TITLE RISK
2018-04-19 CVE-2018-9137 Improper Neutralization of Formula Elements in a CSV File vulnerability in Open-Audit 2.1
Open-AudIT before 2.2 has CSV Injection.
network
low complexity
open-audit CWE-1236
6.8
2018-04-12 CVE-2018-9155 Cross-site Scripting vulnerability in Open-Audit 2.1.1
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the Manage->Attributes section (via the "Name (display)" field to the attributes/create URI).
network
low complexity
open-audit CWE-79
5.4
2018-03-26 CVE-2018-8937 Open Redirect vulnerability in Open-Audit 2.1
An issue was discovered in Open-AudIT Professional 2.1.
network
low complexity
open-audit CWE-601
6.1
2018-03-25 CVE-2018-8979 Cross-site Scripting vulnerability in Open-Audit 2.1
Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.
network
low complexity
open-audit CWE-79
8.8
2018-03-25 CVE-2018-8978 Cross-site Scripting vulnerability in Open-Audit 2.1
Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI.
network
low complexity
open-audit CWE-79
5.4
2018-03-22 CVE-2018-8903 Cross-site Scripting vulnerability in Open-Audit 2.1
Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.
network
low complexity
open-audit CWE-79
5.4