Mind
Imind Server: vulnerabilities and CVEs
Imind Server has 3 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs3
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-25399 | High (7.8) | 1.0% | — | Nov 5, 2020 | Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat. |
| CVE-2020-25398 | High (8.8) | 2.0% | — | Nov 5, 2020 | CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality. |
| CVE-2020-24765 | High (7.5) | 6.8% | — | Oct 20, 2020 | InterMind iMind Server through 3.13.65 allows remote unauthenticated attackers to read the self-diagnostic archive via a direct api/rs/monitoring/rs/api/system/dump-diagnostic-info?server=127.0.0.1 request. |