Search CVE reports
1 – 10 of 15 results
CVE-2024-48708
Medium priorityCollabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php under action = adduser/edituser.
1 affected package
collabtive
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
collabtive | Not in release | Not in release | Not in release | — | Needs evaluation |
CVE-2024-48707
Medium priorityCollabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php file.
1 affected package
collabtive
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
collabtive | Not in release | Not in release | Not in release | — | Needs evaluation |
CVE-2024-48706
Medium priorityCollabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.
1 affected package
collabtive
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
collabtive | Not in release | Not in release | Not in release | — | Needs evaluation |
CVE-2024-46240
Medium priorityCollabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters under action=addcust within admin.php file.
1 affected package
collabtive
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
collabtive | Not in release | Not in release | Not in release | — | Needs evaluation |
CVE-2022-29221
Medium prioritySome fixes available 9 of 32
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or...
6 affected packages
collabtive, galette, gosa, postfixadmin, smarty3, smarty4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
collabtive | — | — | — | — | Needs evaluation |
galette | — | — | — | — | Needs evaluation |
gosa | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
postfixadmin | Not affected | Fixed | Fixed | Fixed | Not affected |
smarty3 | Fixed | Fixed | Needs evaluation | Needs evaluation | Needs evaluation |
smarty4 | Needs evaluation | — | — | — | — |
CVE-2021-3298
Medium priorityCollabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.
1 affected package
collabtive
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
collabtive | Not in release | Not in release | Not in release | Not in release | Vulnerable |
CVE-2020-13655
Medium priorityAn issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and...
1 affected package
collabtive
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
collabtive | — | Not in release | Not in release | Not in release | Not affected |
CVE-2015-0258
Medium priorityMultiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2)...
1 affected package
collabtive
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
collabtive | — | — | Not in release | Not in release | Fixed |
CVE-2019-8935
Medium priorityCollabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.
1 affected package
collabtive
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
collabtive | — | — | — | Not in release | Not affected |
CVE-2014-3247
Medium priorityCross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php.
1 affected package
collabtive
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
collabtive | — | — | — | Not in release | Not affected |