Skip to main content

Vendor/product archive

rws / worldserver CVEs

Beta · best-effort

7 CVEs tagged to rws / worldserver3 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-50849

Published Nov 18, 2024

A Stored Cross-Site Scripting (XSS) vulnerability in the "Rules" functionality of WorldServer v11.8.2 allows a remote authenticated attacker to execute arbitrary JavaScript code.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50848

Published Nov 18, 2024

An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute ar…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34270

Published Feb 29, 2024

An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-34269

Published Feb 29, 2024

An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34268

Published Dec 25, 2023

An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-34267

Published Dec 25, 2023

An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be upload…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-38357

Published Aug 1, 2023

Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1