Edgewall Trac vulnerabilities
3 known vulnerabilities affecting edgewall/trac.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2010-5108P3HIGHCVSS 7.5v0.11.62019-11-13
CVE-2010-5108 [HIGH] CWE-276 CVE-2010-5108: Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be expl
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.
nvd
CVE-2009-4405P4HIGHCVSS 7.5≤ 0.11.5v0.5+33 more2009-12-23
CVE-2009-4405 [HIGH] CVE-2009-4405: Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, p
Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) "policy checks in report results when using alternate formats" or (2) a "check for the 'raw' role that is missing in docutils < 0.6."
ghsanvdosv
CVE-2008-2951P4MEDIUMCVSS 6.1fixed in 0.10.52008-07-27
CVE-2008-2951 [MEDIUM] CWE-601 CVE-2008-2951: Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to re
Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function.
ghsanvdosv