Search CVE reports


Toggle filters

1 – 10 of 15 results


CVE-2024-48708

Medium priority
Needs evaluation

Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php under action = adduser/edituser.

1 affected package

collabtive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
collabtive Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-48707

Medium priority
Needs evaluation

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php file.

1 affected package

collabtive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
collabtive Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-48706

Medium priority
Needs evaluation

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.

1 affected package

collabtive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
collabtive Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-46240

Medium priority
Needs evaluation

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters under action=addcust within admin.php file.

1 affected package

collabtive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
collabtive Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2022-29221

Medium priority

Some fixes available 9 of 32

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or...

6 affected packages

collabtive, galette, gosa, postfixadmin, smarty3, smarty4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
collabtive Needs evaluation
galette Needs evaluation
gosa Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
postfixadmin Not affected Fixed Fixed Fixed Not affected
smarty3 Fixed Fixed Needs evaluation Needs evaluation Needs evaluation
smarty4 Needs evaluation
Show less packages

CVE-2021-3298

Medium priority
Vulnerable

Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.

1 affected package

collabtive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
collabtive Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2020-13655

Medium priority
Not affected

An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and...

1 affected package

collabtive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
collabtive Not in release Not in release Not in release Not affected
Show less packages

CVE-2015-0258

Medium priority
Fixed

Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2)...

1 affected package

collabtive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
collabtive Not in release Not in release Fixed
Show less packages

CVE-2019-8935

Medium priority
Not affected

Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.

1 affected package

collabtive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
collabtive Not in release Not affected
Show less packages

CVE-2014-3247

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php.

1 affected package

collabtive

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
collabtive Not in release Not affected
Show less packages