openasset CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

openasset vulnerability overview

Aggregates CVE and security vulnerability intelligence across all openasset-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting, vendor risk sql injection, and vendor risk csrf and related problems; some flaws may lead to vendor impact session compromise and vendor impact data exposure.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2020-28861 OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application. [email protected] 5.3 0.95% 2020-12-14 2024-11-21
CVE-2020-28860 OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection. [email protected] 8.8 2.42% 2020-12-14 2024-11-21
CVE-2020-28859 OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for reflected cross-site scripting attacks. [email protected] 6.1 0.24% 2020-12-14 2024-11-21
CVE-2020-28858 OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions. [email protected] 8.8 0.37% 2020-12-14 2024-11-21
CVE-2020-28857 OpenAsset Digital Asset Management (DAM) through 12.0.19, does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for stored cross-site scripting attacks. [email protected] 6.1 0.48% 2020-12-14 2024-11-21
CVE-2020-28856 OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls. [email protected] 7.5 0.86% 2020-12-14 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence