Monthly Archive: August 2020

CVE-2020-17451

flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page_content, or page_extracontent parameter, or the acp/acp.php?tn=system&sub=sys_pref prefs_pagename, prefs_pagetitle, or prefs_pagesubtitle parameter. Date published : 2020-08-09 https://lists.openwall.net/full-disclosure/2020/08/07/1 https://sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-flatcore-cms/

CVE-2019-19704

In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm. Date published : 2020-08-08 Home JetBrains Security Bulletin Q2 2020

CVE-2020-15831

JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI. Date published : 2020-08-08 Home JetBrains Security Bulletin Q2 2020

CVE-2020-15830

JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI. Date published : 2020-08-08 Home JetBrains Security Bulletin Q2 2020

CVE-2020-15829

In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs. Date published : 2020-08-08 Home JetBrains Security Bulletin Q2 2020

CVE-2020-15828

In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions. Date published : 2020-08-08 Home JetBrains Security Bulletin Q2 2020

CVE-2020-15827

In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file. Date published : 2020-08-08 Home JetBrains Security Bulletin Q2 2020

CVE-2020-15826

In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have. Date published : 2020-08-08 Home JetBrains Security Bulletin Q2 2020