Adobe Robohelp vulnerabilities

22 known vulnerabilities affecting adobe/robohelp.

Total CVEs
22
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM15

Vulnerabilities

Page 1 of 2
CVE-2023-22272HIGHCVSS 7.5≤ RHS 11.42023-11-17
CVE-2023-22272 [HIGH] CWE-20 CVE-2023-22272: Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnera Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction.
cvelistv5nvd
CVE-2023-22275HIGHCVSS 7.5≤ RHS 11.42023-11-17
CVE-2023-22275 [HIGH] CWE-89 CVE-2023-22275: Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Specia Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction.
cvelistv5nvd
CVE-2023-22274HIGHCVSS 7.5≤ RHS 11.42023-11-17
CVE-2023-22274 [HIGH] CWE-611 CVE-2023-22274: Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML Exter Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction.
cvelistv5nvd
CVE-2023-22273HIGHCVSS 7.2≤ RHS 11.42023-11-17
CVE-2023-22273 [HIGH] CWE-22 CVE-2023-22273: Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to Remote Code Execution by an admin authenticated attacker. Exploitation of this issue does not require user interaction.
cvelistv5nvd
CVE-2023-22268MEDIUMCVSS 6.5≤ RHS 11.42023-11-17
CVE-2023-22268 [MEDIUM] CWE-89 CVE-2023-22268: Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Specia Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to information disclosure by an low-privileged authenticated attacker. Exploitation of this issue does not require user interaction.
cvelistv5nvd
CVE-2022-23201MEDIUMCVSS 6.1≤ 2020.0.7≥ unspecified, ≤ 2020.0.72022-07-15
CVE-2022-23201 [MEDIUM] CWE-79 CVE-2022-23201: Adobe RoboHelp versions 2020.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) Adobe RoboHelp versions 2020.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
cvelistv5nvd
CVE-2022-30670HIGHCVSS 8.8≥ unspecified, ≤ <RHS11U32022-06-16
CVE-2022-30670 [HIGH] CWE-285 CVE-2022-30670: RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vuln RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalation. An authenticated attacker could leverage this vulnerability to achieve full administrator privileges. Exploitation of this issue does not require user interaction.
cvelistv5nvd
CVE-2021-21070MEDIUMCVSS 6.5fixed in 2020.0.4≥ unspecified, ≤ 2020.0.32021-04-19
CVE-2021-21070 [MEDIUM] CWE-427 CVE-2021-21070: Adobe Robohelp version 2020.0.3 (and earlier) is affected by an uncontrolled search path element vul Adobe Robohelp version 2020.0.3 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. An attacker with admin permissions to write to the file system could leverage this vulnerability to escalate privileges.
cvelistv5nvd
CVE-2017-3105MEDIUMCVSS 6.1fixed in 2017.0.1fixed in 12.0.4.4602017-12-01
CVE-2017-3105 [MEDIUM] CWE-601 CVE-2017-3105: Adobe RoboHelp has an Open Redirect vulnerability. This affects versions before RH12.0.4.460 and RH2 Adobe RoboHelp has an Open Redirect vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2.
nvd
CVE-2017-3104MEDIUMCVSS 6.1fixed in 2017.0.1fixed in 12.0.4.4602017-12-01
CVE-2017-3104 [MEDIUM] CWE-79 CVE-2017-3104: Adobe RoboHelp has a cross-site scripting (XSS) vulnerability. This affects versions before RH12.0.4 Adobe RoboHelp has a cross-site scripting (XSS) vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2.
nvd
CVE-2016-7891MEDIUMCVSS 6.1≤ 11.0≥ 2015, ≤ 2015.0.32016-12-15
CVE-2016-7891 [MEDIUM] CWE-79 CVE-2016-7891: Adobe RoboHelp version 2015.0.3 and earlier, RoboHelp 11 and earlier have an input validation issue Adobe RoboHelp version 2015.0.3 and earlier, RoboHelp 11 and earlier have an input validation issue that could be used in cross-site scripting attacks.
nvd
CVE-2016-1035HIGHCVSS 7.5v9v9.0.0.228+1 more2016-04-12
CVE-2016-1035 [HIGH] CWE-200 CVE-2016-1035: Adobe RoboHelp Server 9 before 9.0.1 mishandles SQL queries, which allows attackers to obtain sensit Adobe RoboHelp Server 9 before 9.0.1 mishandles SQL queries, which allows attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2013-5327CRITICALCVSS 10.0v10.02013-10-09
CVE-2013-5327 [CRITICAL] CWE-119 CVE-2013-5327: MDBMS.dll in Adobe RoboHelp 10 allows attackers to execute arbitrary code or cause a denial of servi MDBMS.dll in Adobe RoboHelp 10 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2012-0765MEDIUMCVSS 4.3v8v8.0.1+6 more2012-02-15
CVE-2012-0765 [MEDIUM] CWE-79 CVE-2012-0765: Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 8 and 9 for Word allow remote Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 8 and 9 for Word allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to certain .htm files in (1) template_stock and (2) template_csh directories.
nvd
CVE-2011-2133MEDIUMCVSS 4.3v8v9+1 more2011-08-11
CVE-2011-2133 [MEDIUM] CWE-79 CVE-2011-2133: Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 8 and 9 before 9.0.1.262, and RoboHelp Se Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 8 and 9 before 9.0.1.262, and RoboHelp Server 8 and 9, allows remote attackers to inject arbitrary web script or HTML via the URI, related to template_stock/whutils.js.
nvd
CVE-2011-0613MEDIUMCVSS 4.3v7v82011-05-16
CVE-2011-0613 [MEDIUM] CWE-79 CVE-2011-0613: Multiple cross-site scripting (XSS) vulnerabilities in RoboHelp 7 and 8, and RoboHelp Server 7 and 8 Multiple cross-site scripting (XSS) vulnerabilities in RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to (1) wf_status.htm and (2) wf_topicfs.htm in RoboHTML/WildFireExt/TemplateStock/.
nvd
CVE-2010-2885MEDIUMCVSS 4.3v7v82010-10-26
CVE-2010-2885 [MEDIUM] CWE-79 CVE-2010-2885: Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 7 and 8, and RoboHelp Server 7 and 8, all Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allows remote attackers to inject arbitrary web script or HTML via vectors related to WebHelp generation with RoboHelp for Word.
nvd
CVE-2010-2886MEDIUMCVSS 4.3v7v82010-10-26
CVE-2010-2886 [MEDIUM] CWE-79 CVE-2010-2886: Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 7 and 8, and RoboHelp Server 7 Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2009-0524MEDIUMCVSS 4.3v6v72009-02-26
CVE-2009-0524 [MEDIUM] CWE-79 CVE-2009-0524: Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 6 and 7, and RoboHelp Server 6 and 7, all Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 6 and 7, and RoboHelp Server 6 and 7, allows remote attackers to inject arbitrary web script or HTML via vectors involving files produced by RoboHelp.
nvd
CVE-2009-0523MEDIUMCVSS 4.3v6v72009-02-26
CVE-2009-0523 [MEDIUM] CWE-79 CVE-2009-0523: Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled when displaying the Help Errors log.
nvd