This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Cerebrate-Project First view 2022-02-18
Product Cerebrate Last view 2023-09-05
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:cerebrate-project:cerebrate:*:*:*:*:*:*:*:* 6
cpe:2.3:a:cerebrate-project:cerebrate:1.12:*:*:*:*:*:*:* 2
cpe:2.3:a:cerebrate-project:cerebrate:1.13:*:*:*:*:*:*:* 2
cpe:2.3:a:cerebrate-project:cerebrate:1.14:*:*:*:*:*:*:* 2

Related : CVE

  Date Alert Description
5.3 2023-09-05 CVE-2023-41908

Cerebrate before 1.15 lacks the Secure attribute for the session cookie.

4.3 2023-08-29 CVE-2023-41363

In Cerebrate 1.14, a vulnerability in UserSettingsController allows authenticated users to change user settings of other users.

9.8 2023-03-27 CVE-2023-28883

In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint.

9.1 2023-02-24 CVE-2023-26468

Cerebrate 1.12 does not properly consider organisation_id during creation of API keys.

6.1 2022-02-18 CVE-2022-25321

An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.

5.3 2022-02-18 CVE-2022-25320

An issue was discovered in Cerebrate through 1.4. Username enumeration could occur.

5.3 2022-02-18 CVE-2022-25319

An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled.

4.3 2022-02-18 CVE-2022-25318

An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups.

6.1 2022-02-18 CVE-2022-25317

An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description.

CWE : Common Weakness Enumeration

%idName
66% (2) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
33% (1) CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('...