Filtered by vendor Cozy
                        
                        Subscribe
                        
                        
                    
                    
                
                    Total
                    1 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 | 
|---|---|---|---|---|---|
| CVE-2018-6824 | 1 Cozy | 1 Cozy | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM | 
| Cozy version 2 has XSS allowing remote attackers to obtain administrative access via JavaScript code in the url parameter to the /api/proxy URI, as demonstrated by an XMLHttpRequest call with an 'email:"attacker@example.com"' request, which can be followed by a password reset. | |||||
