Vulnerabilities > Quadbase
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-03-15 | CVE-2020-24985 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Quadbase Espressdashboard 7.0 An issue was discovered in Quadbase EspressReports ES 7 Update 9. | 8.1 |
2021-03-15 | CVE-2020-24982 | Cross-Site Request Forgery (CSRF) vulnerability in Quadbase Espressdashboard 7.0 An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. | 4.3 |
2021-03-11 | CVE-2020-24984 | Cross-Site Request Forgery (CSRF) vulnerability in Quadbase Espressreports ES 7 An issue was discovered in Quadbase EspressReports ES 7 Update 9. | 8.8 |
2021-03-11 | CVE-2020-24983 | Cross-Site Request Forgery (CSRF) vulnerability in Quadbase Espressreports ES 7 An issue was discovered in Quadbase EspressReports ES 7 Update 9. | 8.8 |
2019-06-24 | CVE-2019-9958 | Cross-Site Request Forgery (CSRF) vulnerability in Quadbase Espressreport Enterprise Server 7.0 CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests. | 8.8 |
2019-06-24 | CVE-2019-9957 | Cross-site Scripting vulnerability in Quadbase Espressreport ES 7.0 Stored XSS within Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. | 5.4 |