Vulnerabilities > Opendesa

DATE CVE VULNERABILITY TITLE RISK
2018-07-01 CVE-2018-13040 Cross-Site Request Forgery (CSRF) vulnerability in Opendesa Opensid 18.06Pasca
OpenSID 18.06-pasca has a CSRF vulnerability.
network
opendesa CWE-352
6.8
2018-07-01 CVE-2018-13039 Cross-site Scripting vulnerability in Opendesa Opensid 18.06Pasca
OpenSID 18.06-pasca has reflected Cross Site Scripting (XSS) via the cari parameter, aka an index.php/first?cari= URI.
network
opendesa CWE-79
4.3
2018-07-01 CVE-2018-13038 Unrestricted Upload of File with Dangerous Type vulnerability in Opendesa Opensid 18.06Pasca
OpenSID 18.06-pasca has an Unrestricted File Upload vulnerability via an Attachment Document in the article feature.
network
low complexity
opendesa CWE-434
7.5