Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In September 2019
In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions.
CVSS Score
2.7
EPSS Score
0.001
Published
2019-09-09
A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
CVSS Score
9.8
EPSS Score
0.007
Published
2019-09-09
In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
CVSS Score
7.2
EPSS Score
0.003
Published
2019-09-09
A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data (upload malicious/forged files on a TeamMate server, or replace existing uploaded files with malicious/forged files). The specific flaw exists within the handling of Upload/DomainObjectDocumentUpload.ashx requests because of failure to validate a CSRF token before handling a POST request.
CVSS Score
6.5
EPSS Score
0.002
Published
2019-09-09
res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk. The crash occurs because of a NULL session media object dereference.
CVSS Score
6.5
EPSS Score
0.018
Published
2019-09-09
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error message will display instance internal information.
CVSS Score
5.3
EPSS Score
0.003
Published
2019-09-09
An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.
CVSS Score
7.0
EPSS Score
0.039
Published
2019-09-09
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch.
CVSS Score
4.3
EPSS Score
0.001
Published
2019-09-09
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Insufficient Visual Distinction of Homoglyphs Presented to a User. IDN homographs and RTLO characters are rendered to unicode, which could be used for social engineering.
CVSS Score
5.4
EPSS Score
0.002
Published
2019-09-09
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled.
CVSS Score
9.8
EPSS Score
0.007
Published
2019-09-09


Contact Us

Shodan ® - All rights reserved