Jenzabar
jenzabar
5 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS. |
1Jenzabar 1Internet Campus Solution Nov 21, 2024 May 19, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch 8 has session cookies that are a deterministic function of the username. There is a hard-coded passw...Show more |
2Jenzabar Tiny2Internet Campus Solution MoxiemanagerJun 17, 2026 Mar 25, 2019 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a ZIP archive and using the MoxieManager (for .NET) plugin before 2.1.4 in the mox...Show more |
1Jenzabar 1Internet Campus Solution Jun 17, 2026 Mar 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ICS/StaticPages/AddTestUsers.aspx in Jenzabar JICS (aka Internet Campus Solution) before 2019-02-06 allows remote attackers to create an arbitrary number of accounts with a password of 1234. |
Cross-site scripting (XSS) vulnerability in Jenzabar v8.2.1 through 9.2.0 allows remote attackers to inject arbitrary web script or HTML via the query parameter (aka the Search Field). |