Avolvesoftware / Projectdox
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2014-5132 | Avolve Software ProjectDox 8.1 allows remote attackers to enumerate users via vectors related to email addresses. | MEDIUM | 4.3 | Mar 27, 2018 |
| CVE-2014-5131 | Avolve Software ProjectDox 8.1 makes it easier for remote authenticated users to obtain sensitive information by leveraging ciphertext reuse. | MEDIUM | 6.5 | Mar 27, 2018 |
| CVE-2014-5130 | Avolve Software ProjectDox 8.1 allows remote authenticated users to obtain sensitive information from other users via vectors involving a direct access token. | MEDIUM | 6.5 | Mar 27, 2018 |
| CVE-2014-5129 | Cross-site scripting (XSS) vulnerability in Avolve Software ProjectDox 8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vecto… | MEDIUM | 4.3 | Sep 11, 2014 |
Showing 1 to 4 of 4 CVEs