CVE-2021-27704
Published Nov 12, 2024Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.
Vendor archive
6 CVEs tagged to vendor appspace — 1 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.
Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus a…
Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.
A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups section of the network tab, it is stored as the group name. W…
In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.