rumpus vulnerabilities
CVEs whose affected-version data names the rumpus package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2020-27575High· 8.8Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability
Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which administrators are able to manage users. The edit users form contains a parameter vulnerable to comma…
CVE-2020-27576Medium· 5.4Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site scripting (XSS)
Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site scripting (XSS). Users are able to create folders in the web application. The folder name is insufficiently validated resulting in a stored cross-site scripting vulnerability.
CVE-2020-27574High· 8.8Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF)
Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malicious page, unintended actions could be performed in the web application as the authenticated user.