Vera
Vikisolutions · 3 CVEs
CVE-2019-20484
HIGH
An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project f…
Jan 5, 2021
CVE-2019-20483
MEDIUM
An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user's last name to an XSS Payload, and read…
Jan 5, 2021
CVE-2019-15123
HIGH
The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacke…
Jun 12, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2019-20484 | An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project files by opening the Project URL directly… | HIGH | 0.92% | Jan 5, 2021 |
| CVE-2019-20483 | An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user's last name to an XSS Payload, and read another user's cookie and use that to lo… | MEDIUM | 0.55% | Jan 5, 2021 |
| CVE-2019-15123 | The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .… | HIGH | 2.39% | Jun 12, 2020 |
Showing 1 to 3 of 3 CVEs