Taskcafe Project Taskcafe vulnerabilities
3 known vulnerabilities affecting taskcafe_project/taskcafe.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-26770P2CRITICALCVSS 9.8v0.3.22024-10-04
CVE-2023-26770 [CRITICAL] CWE-284 CVE-2023-26770: TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a regist
TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.
nvd
CVE-2020-25400P3HIGHCVSS 7.5fixed in 0.1.02020-11-17
CVE-2020-25400 [HIGH] CVE-2020-25400: Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remo
Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to access sensitive data such as access token.
nvd
CVE-2023-26771P4MEDIUMCVSS 6.5v0.3.22024-10-04
CVE-2023-26771 [MEDIUM] CWE-79 CVE-2023-26771: Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the fil
Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading a SVG profile picture with a XSS payload on it. An authenticated attacker can exploit this vulnerability by uploading a malicious picture which will trigger the payload when the victim opens the file.
nvd