Spotweb ProjectCVEs & Vulnerabilities

10 CVEs affecting Spotweb Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

spotweb 10
CVE-2021-43725MEDIUM

There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter.

28 Mar 2022
6.1
CVSS
CVE-2021-33966MEDIUM

Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.

21 Jan 2022
5.4
CVSS
CVE-2021-40973MEDIUM

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the lastname parameter.

1 Oct 2021
6.1
CVSS
CVE-2021-40972MEDIUM

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the mail parameter.

1 Oct 2021
6.1
CVSS
CVE-2021-40971MEDIUM

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword1 parameter.

1 Oct 2021
6.1
CVSS
CVE-2021-40970MEDIUM

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the username parameter.

1 Oct 2021
6.1
CVSS
CVE-2021-40969MEDIUM

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the firstname parameter.

1 Oct 2021
6.1
CVSS
CVE-2021-40968MEDIUM

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword2 parameter.

1 Oct 2021
6.1
CVSS
CVE-2021-3286CRITICAL

SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-35545.

26 Jan 2021
9.8
CVSS
CVE-2020-35545CRITICAL

Time-based SQL injection exists in Spotweb 1.4.9 via the query string.

17 Dec 2020
9.8
CVSS
← PrevPage 1 / 1Next →
Spotweb Project CVEs & Vulnerabilities — 10 Tracked