cyberaz0r/Yellowfin-Multiple-Vulnerabilities

cyberaz0r/Yellowfin-Multiple-Vulnerabilities

Releases0
Stars1
Advisory about multiple vulnerabilities discovered in Yellowfin before 9.6.1

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM3.5 LOW

In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially crafted HTTP POST request to the page "ActivityStreamAjax.i4".

7.5 HIGH5 MEDIUM

In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIIAvatarImage.i4".

7.5 HIGH5 MEDIUM

In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIImage.i4".