Vulnerabilities
Vulnerable Software
Buddyboss:  >> Buddyboss  >> 2.2.9  Security Vulnerabilities
Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other users' albums. This vulnerability can be exploited by changing the album identification (id).
CVSS Score
5.4
EPSS Score
0.0
Published
2023-10-03
Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when the associated image is loaded.
CVSS Score
9.0
EPSS Score
0.002
Published
2023-10-03
A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an attacker to store a malicious javascript payload via POST request when sending an invitation.
CVSS Score
6.3
EPSS Score
0.002
Published
2023-10-03


Contact Us

Shodan ® - All rights reserved