Known Vulnerabilities for Spotweb by Spotweb Project
Listed below are 10 of the newest known vulnerabilities associated with "Spotweb" by "Spotweb Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-43725 json | There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote att... | 6.1 - MEDIUM | 2022-03-28 | 2022-03-31 |
| CVE-2021-40973 json | Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote atta... | 6.1 - MEDIUM | 2021-10-01 | 2021-10-04 |
| CVE-2021-40972 json | Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote atta... | 6.1 - MEDIUM | 2021-10-01 | 2021-10-04 |
| CVE-2021-40971 json | Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote atta... | 6.1 - MEDIUM | 2021-10-01 | 2021-10-04 |
| CVE-2021-40970 json | Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote atta... | 6.1 - MEDIUM | 2021-10-01 | 2021-10-04 |
| CVE-2021-40969 json | Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote atta... | 6.1 - MEDIUM | 2021-10-01 | 2021-10-02 |
| CVE-2021-40968 json | Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote atta... | 6.1 - MEDIUM | 2021-10-01 | 2021-10-04 |
| CVE-2021-33966 json | Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via craft... | 5.4 - MEDIUM | 2022-01-21 | 2022-01-26 |
| CVE-2021-3286 json | SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of... | 9.8 - CRITICAL | 2021-01-26 | 2021-01-30 |
| CVE-2020-35545 json | Time-based SQL injection exists in Spotweb 1.4.9 via the query string. | 9.8 - CRITICAL | 2020-12-17 | 2020-12-21 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Spotweb Project | Spotweb | 1.4.9 | |||
| Application | Spotweb Project | Spotweb | 1.4.8 | |||
| Application | Spotweb Project | Spotweb | 1.4.7 | |||
| Application | Spotweb Project | Spotweb | 1.4.6 | |||
| Application | Spotweb Project | Spotweb | 1.4.5 | |||
| Application | Spotweb Project | Spotweb | 1.4.4 | |||
| Application | Spotweb Project | Spotweb | 1.4.3 | |||
| Application | Spotweb Project | Spotweb | 1.4.2 | |||
| Application | Spotweb Project | Spotweb | 1.4.1 | |||
| Application | Spotweb Project | Spotweb | 1.4.0 | |||
| Application | Spotweb Project | Spotweb | 1.3.9 | |||
| Application | Spotweb Project | Spotweb | 1.3.8 | |||
| Application | Spotweb Project | Spotweb | 1.3.7 | |||
| Application | Spotweb Project | Spotweb | 1.3.6 | |||
| Application | Spotweb Project | Spotweb | 1.3.5 | |||
| Application | Spotweb Project | Spotweb | 1.3.4 | |||
| Application | Spotweb Project | Spotweb | 1.3.3 | |||
| Application | Spotweb Project | Spotweb | 1.3.2 | |||
| Application | Spotweb Project | Spotweb | 1.3.1 | |||
| Application | Spotweb Project | Spotweb | 1.3.0 |