Vulnerabilities
Vulnerable Software
Taskcafe Project:  Security Vulnerabilities
TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.
CVSS Score
9.8
EPSS Score
0.003
Published
2024-10-04
Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading a SVG profile picture with a XSS payload on it. An authenticated attacker can exploit this vulnerability by uploading a malicious picture which will trigger the payload when the victim opens the file.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-10-04
Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to access sensitive data such as access token.
CVSS Score
7.5
EPSS Score
0.003
Published
2020-11-17


Contact Us

Shodan ® - All rights reserved