VendorsZendzendto5.21-1
Vulnerabilities

Zend To 5.21-1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2020-8986
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with a large number of requests.
Published 2020-03-24 · Modified
9.8EPSS 0.015
CVE-2020-8985
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
Published 2020-03-24 · Modified
8.8EPSS 0.005
CVE-2020-8984
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
Published 2020-03-24 · Modified
7.5EPSS 0.005