Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Coins_construction_cloud
(Coins\-Global)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 7 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2022-01-24 | CVE-2021-45222 | An issue was discovered in COINS Construction Cloud 11.12. Due to logical flaws in the human ressources interface, it is vulnerable to privilege escalation by HR personnel. | Coins_construction_cloud | 8.8 | ||
2022-01-24 | CVE-2021-45223 | An issue was discovered in COINS Construction Cloud 11.12. Due to insufficient input neutralization, it is vulnerable to denial of service attacks via forced server crashes. | Coins_construction_cloud | 6.5 | ||
2022-01-24 | CVE-2021-45224 | An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a URL parameter. Attackers can trivially alter this code to cause malicious behaviour. The application is therefore vulnerable to reflected XSS via malicious URLs. | Coins_construction_cloud | 6.1 | ||
2022-01-24 | CVE-2021-45225 | An issue was discovered in COINS Construction Cloud 11.12. Due to improper input neutralization, it is vulnerable to reflected cross-site scripting (XSS) via malicious links (affecting the search window and activity view window). | Coins_construction_cloud | 6.1 | ||
2022-01-24 | CVE-2021-45226 | An issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user-controlled HTTP headers, attackers can cause it to send password-reset e-mails pointing to arbitrary websites. | Coins_construction_cloud | 6.5 | ||
2022-04-14 | CVE-2021-45227 | An issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file upload functionality is vulnerable to a persistent Cross-Site Scripting (XSS) attack. | Coins_construction_cloud | 5.4 | ||
2022-04-14 | CVE-2021-45228 | An XSS issue was discovered in COINS Construction Cloud 11.12. Due to insufficient neutralization of user input in the description of a task, it is possible to store malicious JavaScript code in the task description. This is later executed when it is reflected back to the user. | Coins_construction_cloud | 5.4 |