Skip to main content

Vendor archive

appspace CVEs

Beta · best-effort

6 CVEs tagged to vendor appspace1 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2021-27704

Published Nov 12, 2024

Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27990

Published Apr 14, 2021

Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27989

Published Apr 14, 2021

Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27670

Published Feb 25, 2021

Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-27564

Published Feb 22, 2021

A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups section of the network tab, it is stored as the group name. W…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5393

Published Jan 7, 2020

In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1