Known Vulnerabilities for products from Cerebrate-project
Listed below are 9 of the newest known vulnerabilities associated with the vendor "Cerebrate-project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-41908 json | Cerebrate before 1.15 lacks the Secure attribute for the session cookie. | 5.3 - MEDIUM | 2023-09-05 | 2023-09-08 |
| CVE-2023-41363 json | In Cerebrate 1.14, a vulnerability in UserSettingsController allows authenticated users to change user settings of other user... | 4.3 - MEDIUM | 2023-08-29 | 2023-08-31 |
| CVE-2023-28883 json | In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint. | 9.8 - CRITICAL | 2023-03-27 | 2024-01-09 |
| CVE-2023-26468 json | Cerebrate 1.12 does not properly consider organisation_id during creation of API keys. | 9.1 - CRITICAL | 2023-02-24 | 2023-03-03 |
| CVE-2022-25321 json | An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component. | 6.1 - MEDIUM | 2022-02-18 | 2023-12-21 |
| CVE-2022-25320 json | An issue was discovered in Cerebrate through 1.4. Username enumeration could occur. | 5.3 - MEDIUM | 2022-02-18 | 2023-12-21 |
| CVE-2022-25319 json | An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled. | 5.3 - MEDIUM | 2022-02-18 | 2023-12-21 |
| CVE-2022-25318 json | An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and mod... | 4.3 - MEDIUM | 2022-02-18 | 2023-11-03 |
| CVE-2022-25317 json | An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled... | 6.1 - MEDIUM | 2022-02-18 | 2023-09-28 |