PatchSiren

Kabona Ab CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Kabona Ab CVE published 2017-02-13

CVE-2016-8376

CVE-2016-8376 is an open redirect / unvalidated forward issue in Kabona AB WebDatorCentral (WDC) prior to version 3.4.0. The weakness is classified as CWE-601 and was assigned a CVSS 3.0 score of 6.1 (medium). The key risk is not just redirection itself: the issue can be chained with authenticated vulnerabilities, increasing the impact of attacks that rely on user trust, session flow, or misleading navigation.

HIGH Kabona Ab CVE published 2017-02-13

CVE-2016-8356

CVE-2016-8356 is a cross-site scripting flaw in Kabona AB WebDatorCentral (WDC) before version 3.4.0. According to the CVE and NVD record, web server URL inputs were not sanitized correctly, which could allow XSS when an attacker can influence those inputs and a user processes the resulting content. NVD scores the issue 8.2 HIGH, reflecting network exposure, required user interaction, and potential impact [truncated]

CRITICAL Kabona Ab CVE published 2017-02-13

CVE-2016-8347

CVE-2016-8347 describes an authentication weakness in Kabona AB WebDatorCentral (WDC) prior to version 3.4.0. Because the application did not limit authentication attempts, it could allow brute-force login attacks against exposed WDC deployments.