Skip to main content

Vendor/product archive

posh_project / posh CVEs

Beta · best-effort

4 CVEs tagged to posh_project / posh0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2014-2214

Published Nov 22, 2019

Multiple cross-site scripting (XSS) vulnerabilities in POSH (aka Posh portal or Portaneo) 3.0 through 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2213

Published Nov 22, 2019

Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing att…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2212

Published Apr 1, 2014

The remember me feature in portal/scr_authentif.php in POSH (aka Posh portal or Portaneo) 3.0, 3.2.1, 3.3.0, and earlier stores the username and MD5 digest of the password in clea…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2211

Published Mar 3, 2014

SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows remote attackers to execute arbitrary SQL commands via the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1