Lucene search

K

Verse Security Vulnerabilities

cve
cve

CVE-2023-37496

HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive...

8.3CVSS

5.3AI Score

0.0005EPSS

2023-08-01 01:15 AM
12
cve
cve

CVE-2023-28013

HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session...

6.5CVSS

6.1AI Score

0.001EPSS

2023-07-26 11:15 PM
23
cve
cve

CVE-2021-27788

HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability. By tricking a user into clicking a crafted URL, a remote unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other...

8.3CVSS

6.1AI Score

0.001EPSS

2023-03-10 09:15 PM
19
cve
cve

CVE-2020-4099

The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the...

7.5CVSS

7.4AI Score

0.001EPSS

2022-11-01 06:15 PM
23
3
cve
cve

CVE-2021-27768

Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this specific scenario, the application's network traffic was intercepted using a proxy server set up in 'transparent' mode.....

6.3CVSS

5.5AI Score

0.001EPSS

2022-05-12 10:15 PM
43
4
cve
cve

CVE-2021-24466

The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the settings. Due to the lack of sanitisation in the settings and verses, this could....

6.1CVSS

6AI Score

0.001EPSS

2021-08-16 11:15 AM
24
cve
cve

CVE-2021-24410

The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, and do not sanitise or escape them when outputting them back in the page. This could allow attackers to make a logged in admin change the settings, as well as add malicious verses.....

6.1CVSS

6.1AI Score

0.001EPSS

2021-08-16 11:15 AM
33
6
cve
cve

CVE-2020-4080

HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security.....

6.1CVSS

6AI Score

0.002EPSS

2020-12-18 10:15 PM
24
3
cve
cve

CVE-2020-4100

"HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded natively at runtime;.....

4.4CVSS

4.9AI Score

0.0004EPSS

2020-07-15 01:15 PM
16
cve
cve

CVE-2017-14115

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures ssh-permanent-enable WAN SSH logins to the remotessh account with the 5SaP9I26 password, which allows remote attackers to access a "Terminal shell v1.0" service, and...

8.1CVSS

8.1AI Score

0.008EPSS

2017-09-03 07:29 PM
36
cve
cve

CVE-2017-10793

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, configures an sbdc.ha WAN TCP service on port 61001 with the bdctest account and the bdctest password, which allows remote attackers to obtain sensitive...

8.1CVSS

7.8AI Score

0.014EPSS

2017-09-03 07:29 PM
30
cve
cve

CVE-2017-14117

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures an unauthenticated proxy service on WAN TCP port 49152, which allows remote attackers to establish arbitrary TCP connections to intranet hosts by sending \x2a\xce\x01...

5.9CVSS

6.6AI Score

0.03EPSS

2017-09-03 07:29 PM
32
cve
cve

CVE-2017-14116

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver https service with the tech account and an empty password, which allows remote attackers to obtain root privileges by establishing a session on port 49955 and....

8.1CVSS

8AI Score

0.008EPSS

2017-09-03 07:29 PM
29