RealLinkers

2 exploits Active since Oct 2019
CVE-2019-18890 NOMISEC MEDIUM WORKING POC
Redmine < 3.3.10 - Authenticated SQL Injection via Object Query
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
10 stars
CVSS 6.5
CVE-2019-17427 NOMISEC MEDIUM WORKING POC
Redmine < 3.4.11 and 4.0.x < 4.0.4 - Stored Cross-Site Scripting via Textile Formatting
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
1 stars
CVSS 6.1