Spagobi
Eng · 8 CVEs
SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the work…
Jan 21, 2025
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
Jan 21, 2025
A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An…
Jan 21, 2025
SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
Jan 10, 2020
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated user…
Nov 22, 2019
The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which al…
Oct 8, 2014
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary we…
Mar 7, 2014
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary we…
Mar 7, 2014
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-54795 | SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function. | MEDIUM | 0.52% | Jan 21, 2025 |
| CVE-2024-54794 | The script input feature of SpagoBI 3.5.1 allows arbitrary code execution. | CRITICAL | 12.83% | Jan 21, 2025 |
| CVE-2024-54792 | A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another use… | MEDIUM | 0.29% | Jan 21, 2025 |
| CVE-2013-6231 | SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script | HIGH | 9.88% | Jan 10, 2020 |
| CVE-2013-6234 | Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by uploading… | HIGH | 6.71% | Nov 22, 2019 |
| CVE-2014-7296 | The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execu… | MEDIUM | 1.70% | Oct 8, 2014 |
| CVE-2013-6233 | Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description fie… | MEDIUM | 3.21% | Mar 7, 2014 |
| CVE-2013-6232 | Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in… | LOW | 3.64% | Mar 7, 2014 |
Showing 1 to 8 of 8 CVEs