Vulnerabilities (CVE)

Filtered by vendor Hrsale Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-29053 1 Hrsale 1 Hrsale 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
HRSALE 2.0.0 allows XSS via the admin/project/projects_calendar set_date parameter.
CVE-2020-27993 1 Hrsale 1 Hrsale 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files.