Skip to main content

Vendor archive

rws CVEs

Beta · best-effort

10 CVEs tagged to vendor rws3 Critical, 2 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2024-50849

Published Nov 18, 2024

A Stored Cross-Site Scripting (XSS) vulnerability in the "Rules" functionality of WorldServer v11.8.2 allows a remote authenticated attacker to execute arbitrary JavaScript code.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50848

Published Nov 18, 2024

An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute ar…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43025

Published Sep 18, 2024

An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted payload i…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43024

Published Sep 18, 2024

Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary web scripts or HTML via a crafted payloa…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34270

Published Feb 29, 2024

An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-34269

Published Feb 29, 2024

An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34268

Published Dec 25, 2023

An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-34267

Published Dec 25, 2023

An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be upload…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-38357

Published Aug 1, 2023

Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4548

Published Dec 28, 2005

SQL injection vulnerability in the "user area" in RWS Statistics Counter before 2.4.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1