Vulnerabilities
Vulnerable Software
Accela:  >> Civic Platform  >> 19.2  Security Vulnerabilities
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a modified contactSeqNumber value. NOTE: the vendor states "the information that is being queried is authorized for an authenticated user of that application, so we consider this not applicable.
CVSS Score
6.5
EPSS Score
0.068
Published
2021-06-09
Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags and we are unable to reproduce them with the available information.
CVSS Score
6.1
EPSS Score
0.069
Published
2021-06-09
In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are configurable security flags and we are unable to reproduce them with the available information.
CVSS Score
6.1
EPSS Score
0.087
Published
2021-06-07


Contact Us

Shodan ® - All rights reserved