Total
4 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-28111 | 1 Thinkst | 1 Canarytokens | 2025-12-05 | N/A | 6.5 MEDIUM |
|
Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canarytoken's incidents in CSV format. The generation of these CSV files is vulnerable to a CSV Injection vulnerability. This flaw can be used by an attacker who discovers an HTTP-based Canarytoken to target the Canarytoken's owner, if the owner exports the incident history to CSV and opens in a reader application such as Microsoft Excel. The impact is that this issue could lead to co ...
Show More |
|||||
| CVE-2023-22475 | 1 Thinkst | 1 Canarytokens | 2024-11-21 | N/A | 6.3 MEDIUM |
|
Canarytokens is an open source tool which helps track activity and actions on your network. A Cross-Site Scripting vulnerability was identified in the history page of triggered Canarytokens prior to sha-fb61290. An attacker who discovers an HTTP-based Canarytoken (a URL) can use this to execute Javascript in the Canarytoken's trigger history page (domain: canarytokens.org) when the history page is later visited by the Canarytoken's creator.
This vulnerability could be used to disable or delete ...
Show More |
|||||
| CVE-2022-31113 | 1 Thinkst | 1 Canarytokens | 2024-11-21 | 4.3 MEDIUM | 6.3 MEDIUM |
|
Canarytokens is an open source tool which helps track activity and actions on your network. A Cross-Site Scripting vulnerability was identified in the history page of triggered Canarytokens. This permits an attacker who recognised an HTTP-based Canarytoken (a URL) to execute Javascript in the Canarytoken's history page (domain: canarytokens.org) when the history page is later visited by the Canarytoken's creator. This vulnerability could be used to disable or delete the affected Canarytoken, or ...
Show More |
|||||
| CVE-2019-9768 | 1 Thinkst | 1 Canarytokens | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for attackers to estimate whether a Word document contains a token.
|
|||||