BDSA-2021-4038 |
|
High |
Jan 18, 2022 |
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a vict
more...
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a victim's instance of Croogo, which could be used to steal session tokens, cookies, or other sensitive information.
less...
|
|
BDSA-2021-4037 |
|
High |
Jan 18, 2022 |
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a vict
more...
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a victim's browser, which could be used to steal session tokens, cookies, or other sensitive information.
less...
|
|
BDSA-2021-4036 |
|
High |
Jan 18, 2022 |
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a vict
more...
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a victim's browser, which could be used to steal session tokens, cookies, or other sensitive information.
less...
|
|
BDSA-2021-4035 |
|
High |
Jan 18, 2022 |
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a vict
more...
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a victim's instance of Croogo, which could be used to steal session tokens, cookies, or other sensitive information.
less...
|
|
BDSA-2021-3669 |
|
Medium |
Dec 07, 2021 |
Croogo is vulnerable to remote code execution (RCE) due to unsafe file upload functionality. An authenticated attacker with administrator credentials c
more...
Croogo is vulnerable to remote code execution (RCE) due to unsafe file upload functionality. An authenticated attacker with administrator credentials could upload, and execute, arbitrary PHP scripts via the "Attachments" feature of the File Manager component.
less...
|
|