Vulnerabilities > Yellowfinbi > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-10-14 | CVE-2021-36387 | Cross-site Scripting vulnerability in Yellowfinbi Yellowfin In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially crafted HTTP POST request to the page "ActivityStreamAjax.i4". | 5.4 |
2019-07-26 | CVE-2019-1010147 | Cross-site Scripting vulnerability in multiple products Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. | 5.4 |