CVE-2020-25399
Published Nov 5, 2020Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.
Vendor/product archive
3 CVEs tagged to mind / imind_server — 0 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.
Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
InterMind iMind Server through 3.13.65 allows remote unauthenticated attackers to read the self-diagnostic archive via a direct api/rs/monitoring/rs/api/system/dump-diagnostic-inf…