Filtered by vendor Openasset
Subscriptions
Filtered by product Digital Asset Management
Subscriptions
Total
6 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2020-28857 | 1 Openasset | 1 Digital Asset Management | 2024-08-04 | 6.1 Medium |
OpenAsset Digital Asset Management (DAM) through 12.0.19, does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for stored cross-site scripting attacks. | ||||
CVE-2020-28856 | 1 Openasset | 1 Digital Asset Management | 2024-08-04 | 7.5 High |
OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls. | ||||
CVE-2020-28861 | 1 Openasset | 1 Digital Asset Management | 2024-08-04 | 5.3 Medium |
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application. | ||||
CVE-2020-28859 | 1 Openasset | 1 Digital Asset Management | 2024-08-04 | 6.1 Medium |
OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for reflected cross-site scripting attacks. | ||||
CVE-2020-28858 | 1 Openasset | 1 Digital Asset Management | 2024-08-04 | 8.8 High |
OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions. | ||||
CVE-2020-28860 | 1 Openasset | 1 Digital Asset Management | 2024-08-04 | 8.8 High |
OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection. |
Page 1 of 1.