Filtered by vendor Inveniosoftware
Subscribe
Total
5 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-43781 | 1 Inveniosoftware | 1 Invenio-drafts-resources | 2024-11-21 | 4.0 MEDIUM | 6.4 MEDIUM |
|
Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable in a default installation of InvenioRDM. An authenticated a user is able via REST API calls to publish draft records of other users if they know the record identifier and the draft validates (e.g. all require fields filled ...
Show More |
|||||
| CVE-2019-1020019 | 1 Inveniosoftware | 1 Invenio-previewer | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
invenio-previewer before 1.0.0a12 allows XSS.
|
|||||
| CVE-2019-1020006 | 1 Inveniosoftware | 1 Invenio-app | 2024-11-21 | 5.8 MEDIUM | 6.1 MEDIUM |
|
invenio-app before 1.1.1 allows host header injection.
|
|||||
| CVE-2019-1020005 | 1 Inveniosoftware | 1 Invenio-communities | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
invenio-communities before 1.0.0a20 allows XSS.
|
|||||
| CVE-2019-1020003 | 1 Inveniosoftware | 1 Invenio-records | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
invenio-records before 1.2.2 allows XSS.
|
|||||