Vulnerabilities (CVE)

Filtered by vendor Inveniosoftware
Angry Yack Logo
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-43781 1 Inveniosoftware 1 Invenio-drafts-resources 2024-11-21 4.0 MEDIUM 6.4 MEDIUM
Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable in a default installation of InvenioRDM. An authenticated a user is able via REST API calls to publish draft records of other users if they know the record identifier and the draft validates (e.g. all require fields filled ...

Show More

CVE-2019-1020019 1 Inveniosoftware 1 Invenio-previewer 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
invenio-previewer before 1.0.0a12 allows XSS.
CVE-2019-1020006 1 Inveniosoftware 1 Invenio-app 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
invenio-app before 1.1.1 allows host header injection.
CVE-2019-1020005 1 Inveniosoftware 1 Invenio-communities 2024-11-21 3.5 LOW 5.4 MEDIUM
invenio-communities before 1.0.0a20 allows XSS.
CVE-2019-1020003 1 Inveniosoftware 1 Invenio-records 2024-11-21 3.5 LOW 5.4 MEDIUM
invenio-records before 1.2.2 allows XSS.