Vulnerabilities > Open Audit

DATE CVE VULNERABILITY TITLE RISK
2018-04-19 CVE-2018-9137 Improper Neutralization of Formula Elements in a CSV File vulnerability in Open-Audit 2.1
Open-AudIT before 2.2 has CSV Injection.
3.5
2018-04-12 CVE-2018-9155 Cross-site Scripting vulnerability in Open-Audit 2.1.1
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the Manage->Attributes section (via the "Name (display)" field to the attributes/create URI).
network
open-audit CWE-79
3.5
2018-03-26 CVE-2018-8937 Open Redirect vulnerability in Open-Audit 2.1
An issue was discovered in Open-AudIT Professional 2.1.
5.8
2018-03-25 CVE-2018-8979 Cross-Site Request Forgery (CSRF) vulnerability in Open-Audit 2.1
Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.
6.8
2018-03-25 CVE-2018-8978 Cross-site Scripting vulnerability in Open-Audit 2.1
Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI.
network
open-audit CWE-79
3.5
2018-03-22 CVE-2018-8903 Cross-site Scripting vulnerability in Open-Audit 2.1
Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.
network
open-audit CWE-79
3.5