Labkey Server
Labkey · 6 CVEs
An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code thro…
Oct 29, 2019
An issue was discovered in LabKey Server 19.1.0. The display name of a user is vulnerable to stored XSS that can execut…
Oct 29, 2019
An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization…
Oct 29, 2019
Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker…
Jan 30, 2019
An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL para…
Jan 30, 2019
Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an…
Jan 30, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2019-9926 | An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a /reports-viewScriptReport.view CSR… | HIGH | 1.92% | Oct 29, 2019 |
| CVE-2019-9758 | An issue was discovered in LabKey Server 19.1.0. The display name of a user is vulnerable to stored XSS that can execute on administrators from security/permis… | MEDIUM | 1.04% | Oct 29, 2019 |
| CVE-2019-9757 | An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualization-expor… | HIGH | 37.34% | Oct 29, 2019 |
| CVE-2019-3913 | Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker to unmount any drive on the system lead… | MEDIUM | 1.74% | Jan 30, 2019 |
| CVE-2019-3912 | An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote a… | MEDIUM | 4.83% | Jan 30, 2019 |
| CVE-2019-3911 | Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remote attacker to inje… | MEDIUM | 3.81% | Jan 30, 2019 |
Showing 1 to 6 of 6 CVEs