Known Vulnerabilities
CVE-2023-4815
Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3.
CVE-2023-4127
Race Condition within a Thread in GitHub repository answerdev/answer prior to v1.1.1.
CVE-2023-4126
Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.
CVE-2023-4125
Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.
CVE-2023-4124
Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1.
CVE-2023-2590
Missing Authorization in GitHub repository answerdev/answer prior to 1.0.9.
CVE-2023-1974
Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8.
CVE-2023-1975
Insertion of Sensitive Information Into Sent Data in GitHub repository answerdev/answer prior to 1.0.8.
CVE-2023-1976
Password Aging with Long Expiration in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1541
Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1540
Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1542
Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1543
Insufficient Session Expiration in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1537
Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1538
Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1535
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7.
CVE-2023-1539
Improper Restriction of Excessive Authentication Attempts in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1536
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7.
CVE-2023-1243
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1240
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1245
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1244
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1239
Cross-site Scripting (XSS) - Reflected in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1241
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1238
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1237
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1242
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-0934
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.5.
CVE-2023-0742
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
CVE-2023-0741
Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.
CVE-2023-0740
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
CVE-2023-0739
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitHub repository answerdev/answer prior to 1.0.4.
CVE-2023-0744
Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.
CVE-2023-0743
Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.