Montala Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Montala products.
Products
- ResourceSpace2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-25662HIGH | ResourceSpace 8.6 SQL Injection via watched_searches.phpResourceSpace 8.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'ref' parameter. Attackers can send GET requests to the watched_searches.php endpoint with crafted SQL payloads to extract sensitive database information including usernames and credentials. CWE-89Apr 5, 2026 | CVSS8.8v4.0 | EPSS0.422% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-41951MEDIUM | montala resourcespace Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_sso/pages/index.php via the wordpress_user parameter. If an attacker is able to persuade a victim to visit a crafted URL, malicious JavaScript content may be executed within the context of the victim's browser. | CVSS6.1v3.1 | EPSS77.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |