Search Results (27 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-36608 1 Webtareas Project 1 Webtareas 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php.
CVE-2020-25735 1 Webtareas Project 1 Webtareas 2024-11-21 6.1 Medium
webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/claim_type.php, projects/editproject.php, and general/newnotifications.php.
CVE-2020-25734 1 Webtareas Project 1 Webtareas 2024-11-21 5.3 Medium
webTareas through 2.1 allows files/Default/ Directory Listing.
CVE-2020-25733 1 Webtareas Project 1 Webtareas 2024-11-21 7.5 High
webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.
CVE-2020-23660 1 Webtareas Project 1 Webtareas 2024-11-21 5.4 Medium
webTareas v2.1 is affected by Cross Site Scripting (XSS) on "Search."
CVE-2020-23069 1 Webtareas Project 1 Webtareas 2024-11-21 6.5 Medium
Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files.
CVE-2020-14973 1 Webtareas Project 1 Webtareas 2024-11-21 6.1 Medium
The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS) vulnerability via the query string.