spiceworks vulnerabilities
CVEs whose affected-version data names the spiceworks package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2020-23451High· 8.8Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.
Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.
▾ Twilightspiceworks · spiceworksEPSS 0.59%via NVD
CVE-2020-23450Medium· 5.4Spiceworks Version <= 7.5.00107 is affected by XSS
Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitization.
▾ Sunlitspiceworks · spiceworksEPSS 0.60%via NVD