Lucene search

K

Ponton Security Vulnerabilities

cve
cve

CVE-2021-45889

An issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as demonstrated by private/index.jsp?partners/ShowNonLocalPartners.do?localID= or private/index.jsp or private/index.jsp?database/databaseTab.jsp or...

5.4CVSS

5.5AI Score

0.001EPSS

2022-03-13 02:15 AM
63
cve
cve

CVE-2021-45887

An issue was discovered in PONTON X/P Messenger before 3.11.2. Due to path traversal in private/SchemaSetUpload.do for uploaded ZIP files, an executable script can be uploaded by web application administrators, giving the attacker remote code execution on the underlying server via an imgs/*.jsp...

9.8CVSS

9.6AI Score

0.007EPSS

2022-03-13 02:15 AM
69
cve
cve

CVE-2021-45886

An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable to a weakened version of CSRF, where an arbitrary token of a low-privileged user (such as operator) can be used to confirm actions of higher-privileged ones...

8.8CVSS

8.5AI Score

0.001EPSS

2022-03-13 02:15 AM
64
cve
cve

CVE-2021-45888

An issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of every page of the web application is vulnerable to XSS: it allows injection of JavaScript into its nodes. Creating such nodes is only possible for users who have the role...

4.8CVSS

5.3AI Score

0.001EPSS

2022-03-13 02:15 AM
63