Vulnerabilities
Vulnerable Software
Squaredup:  Security Vulnerabilities
CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.
CVSS Score
6.5
EPSS Score
0.008
Published
2021-02-03
A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid usernames.
CVSS Score
3.7
EPSS Score
0.009
Published
2021-02-03
SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content in iframe or by uploading an SVG that contained a script.
CVSS Score
5.4
EPSS Score
0.009
Published
2021-02-03


Contact Us

Shodan ® - All rights reserved