Products: 1
    Vulnerabilities: 3
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-28408

    The server in Dundas BI through 8.0.0.1001 allows XSS via an HTML label when creating or editing a dashboard.

    Last Modified: Nov 21, 2024
    Published: Nov 10, 2020

    CVE-2020-28409

    The server in Dundas BI through 8.0.0.1001 allows XSS via addition of a Component (e.g., a button) when events such as click, hover, etc. occur.

    Last Modified: Nov 21, 2024
    Published: Nov 10, 2020

    CVE-2018-18569

    The Dundas BI server before 5.0.1.1010 is vulnerable to a Server-Side Request Forgery attack, allowing an attacker to forge arbitrary requests (with certain restrictions) that will be executed on behalf of the attacker, via the viewUrl parameter of the "export the dashboard as an image" feature. This could be leveraged to provide a proxy to attack other servers (internal or external) or to perform network scans of external or internal networks.

    Last Modified: Nov 21, 2024
    Published: Feb 11, 2019
    Items Per Page
    Dundas Vulnerabilities & Security CVEs | CVE-DB