causefx/Organizr

causefx/Organizr

Releases66
Frequency1 week 5 days
Last Release
Stars5.77K
HTPC/Homelab Services Organizer - Written in PHP

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php.

6.1 MEDIUM

Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php.

9.8 CRITICAL

Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php.

5.4 MEDIUM3.5 LOW

Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200.

7.5 HIGH5 MEDIUM

Allowing long password leads to denial of service in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

7.5 HIGH5 MEDIUM

Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

9 CRITICAL3.5 LOW

Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

8.4 HIGH6 MEDIUM

Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub repository causefx/organizr prior to 2.1.1810. Account takeover and privilege escalation

9 CRITICAL3.5 LOW

Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

9 CRITICAL3.5 LOW

Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.