Munkireport Project

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-15882

    A CSRF issue in manager/delete_machine/{id} in MunkiReport before 5.6.3 allows attackers to delete arbitrary machines from the MunkiReport database.

    Last Modified: Nov 21, 2024
    Published: Jul 23, 2020

    CVE-2020-15884

    A SQL injection vulnerability in TableQuery.php in MunkiReport before 5.6.3 allows attackers to execute arbitrary SQL commands via the order[0][dir] field on POST requests to /datatables/data.

    Last Modified: Nov 21, 2024
    Published: Jul 23, 2020

    CVE-2020-15885

    A Cross-Site Scripting (XSS) vulnerability in the comment module before 4.0 for MunkiReport allows remote attackers to inject arbitrary web script or HTML by posting a new comment.

    Last Modified: Nov 21, 2024
    Published: Jul 23, 2020

    CVE-2020-10190

    An issue was discovered in MunkiReport before 5.3.0. An authenticated user could achieve SQL Injection in app/models/tablequery.php by crafting a special payload on the /datatables/data endpoint.

    Last Modified: Nov 21, 2024
    Published: Mar 09, 2020

    CVE-2020-10191

    An issue was discovered in MunkiReport before 5.3.0. An authenticated actor can send a custom XSS payload through the /module/comment/save endpoint. The payload will be executed by any authenticated users browsing the application. This concerns app/controllers/client.php:detail.

    Last Modified: Nov 21, 2024
    Published: Mar 09, 2020
    Items Per Page