📦 Archer

by Archerirm

🔍 What is Archer?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-41705

HIGH CVSS 7.1 Jul 25, 2024

A stored cross-site scripting (XSS) vulnerability in Archer Platform allows authenticated attackers to inject malicious scripts into application data stores. When other users access these stores throu...

CVE-2024-34089

HIGH CVSS 7.3 May 6, 2024

A stored cross-site scripting (XSS) vulnerability in Archer Platform 6 allows authenticated attackers to inject malicious scripts into application data stores. When other users access the compromised ...

CVE-2024-34091

HIGH CVSS 7.3 May 6, 2024

A stored cross-site scripting (XSS) vulnerability in Archer Platform 6 allows authenticated attackers to inject malicious HTML/JavaScript into the application's data store. When other users access the...

CVE-2024-26313

HIGH CVSS 7.3 Mar 8, 2024

Archer Platform 6.x contains a stored cross-site scripting (XSS) vulnerability that allows authenticated malicious users to inject and store malicious HTML/JavaScript in the application's data store. ...

CVE-2023-48641

HIGH CVSS 7.5 Dec 12, 2023

Archer Platform 6.x contains an insecure direct object reference vulnerability that allows authenticated malicious users in multi-instance installations to bypass authorization checks by manipulating ...

CVE-2023-45358

HIGH CVSS 8.5 Oct 17, 2023

This stored cross-site scripting (XSS) vulnerability in Archer Platform allows authenticated attackers to inject malicious scripts into the application's data store. When other users access the compro...

CVE-2023-32759

HIGH CVSS 7.5 Jul 14, 2023

This vulnerability in Archer Platform allows authenticated attackers to access sensitive information by crafting specific URLs. It affects Archer Platform versions before 6.13, specifically those not ...

CVE-2023-32761

HIGH CVSS 8.1 Jul 14, 2023

This CSRF vulnerability in Archer Platform allows authenticated attackers to execute arbitrary code via crafted requests. It affects Archer Platform versions before 6.13, specifically those not update...

CVE-2023-30639

HIGH CVSS 7.1 May 1, 2023

Archer Platform versions before 6.12 P6 HF1 contain a stored cross-site scripting (XSS) vulnerability that allows authenticated attackers to inject malicious scripts into the application data store. W...

CVE-2024-49210

MEDIUM CVSS 5.2 Oct 22, 2024

This vulnerability allows reflected cross-site scripting (XSS) in Archer Platform's iView List UX page. An unauthenticated attacker can trick a victim into visiting a malicious link containing JavaScr...

CVE-2024-49208

MEDIUM CVSS 5.9 Oct 22, 2024

Archer Platform 2024.03 versions before 2024.08 have an authorization bypass vulnerability in supporting application files. This allows remote unprivileged attackers to elevate privileges and delete s...

CVE-2024-41707

MEDIUM CVSS 4.8 Jul 25, 2024

This vulnerability allows authenticated Archer Platform users to inject malicious HTML content into the application's data store. When other users access this stored content through their browsers, th...

CVE-2024-26312

MEDIUM CVSS 4.3 May 6, 2024

Archer Platform 6 contains a sensitive information disclosure vulnerability where authenticated attackers can access sensitive data through popup warning messages. This affects organizations using Arc...

CVE-2024-34093

MEDIUM CVSS 5.3 May 6, 2024

This vulnerability in Archer Platform 6 allows unauthenticated attackers to bypass IP whitelisting controls when the X-Forwarded-For header is enabled. Attackers can potentially access restricted reso...