« Back to list

Mind

Imind Server: vulnerabilities and CVEs

Imind Server has 3 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs3
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-25399High (7.8)1.0%—Nov 5, 2020
Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.
CVE-2020-25398High (8.8)2.0%—Nov 5, 2020
CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.
CVE-2020-24765High (7.5)6.8%—Oct 20, 2020
InterMind iMind Server through 3.13.65 allows remote unauthenticated attackers to read the self-diagnostic archive via a direct api/rs/monitoring/rs/api/system/dump-diagnostic-info?server=127.0.0.1 request.