Product
webtareas project webtareas
27 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-53972
CVE-2023-53971
CVE-2022-44962
CVE-2022-44961
CVE-2022-44960
CVE-2022-44959
CVE-2022-44957
CVE-2022-44956
CVE-2022-44955
CVE-2022-44954
CVE-2022-44953
CVE-2022-44291
CVE-2022-44290
CVE-2021-36609
CVE-2021-36608
CVE-2021-43481
CVE-2021-41920
CVE-2021-41919
CVE-2021-41918
CVE-2021-41917
CVE-2021-41916
CVE-2020-23069
CVE-2020-25735
CVE-2020-25734
CVE-2020-25733
CVE-2020-23660
CVE-2020-14973
all versions
WebTareas 2.4 contains a SQL injection vulnerability in the webTareasSID cookie parameter that allows unauthenticated attackers to
all versions
WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat
all versions
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /calendar/viewcalendar.php.
all versions
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /forums/editforum.php. This
all versions
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /general/search.php?searchty
all versions
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /meetings/listmeetings.php.
all versions
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. Th
all versions
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php.
all versions
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the Chat function. This vulnerability allo
all versions
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /contacts/listcontacts.php.
all versions
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /linkedcontent/listfiles.php
all versions
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
all versions
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
all versions
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder.php.
all versions
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php.
< 2.4
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.
<= 2.4
webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endp
<= 2.4
webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restricti
<= 2.4
webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitizatio
<= 2.4
webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or editing a clie
<= 2.4
A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new ad
all versions
Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious use
<= 2.1
webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, admi
<= 2.1
webTareas through 2.1 allows files/Default/ Directory Listing.
<= 2.1
webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.
all versions
webTareas v2.1 is affected by Cross Site Scripting (XSS) on "Search."
all versions
The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS) vulnerab