Vulnerabilities (CVE)

Filtered by vendor Webtareas Project Subscribe
Filtered by product Webtareas
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25733 1 Webtareas Project 1 Webtareas 2024-02-28 5.0 MEDIUM 7.5 HIGH
webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.
CVE-2020-25735 1 Webtareas Project 1 Webtareas 2024-02-28 4.3 MEDIUM 6.1 MEDIUM
webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/claim_type.php, projects/editproject.php, and general/newnotifications.php.
CVE-2020-25734 1 Webtareas Project 1 Webtareas 2024-02-28 5.0 MEDIUM 5.3 MEDIUM
webTareas through 2.1 allows files/Default/ Directory Listing.
CVE-2020-23660 1 Webtareas Project 1 Webtareas 2024-02-28 3.5 LOW 5.4 MEDIUM
webTareas v2.1 is affected by Cross Site Scripting (XSS) on "Search."
CVE-2020-14973 1 Webtareas Project 1 Webtareas 2024-02-28 4.3 MEDIUM 6.1 MEDIUM
The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS) vulnerability via the query string.