
CVE-2023-22268 – ZDI-CAN-21308: Adobe RoboHelp Server getRHSGroupsForRoles SQL Injection Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-22268
15 Nov 2023 — Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to information disclosure by an low-privileged authenticated attacker. Exploitation of this issue does not require user interaction. Las versiones 11.4 y anteriores de Adobe RoboHelp Server se ven afectadas por una neutralización inadecuada de elementos especiales utilizados en una vulnerabilidad de comando SQL ("inyección SQL")... • https://helpx.adobe.com/security/products/robohelp-server/apsb23-53.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-22272 – ZDI-CAN-21309: Adobe RoboHelp Server resolveDistinguishedName LDAP Injection Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-22272
15 Nov 2023 — Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction. Las versiones 11.4 y anteriores de Adobe RoboHelp Server se ven afectadas por una vulnerabilidad de validación de entrada incorrecta que podría provocar la divulgación de información por parte de un atacante no autenticado. La explotación de este problema no requiere l... • https://helpx.adobe.com/security/products/robohelp-server/apsb23-53.html • CWE-20: Improper Input Validation •

CVE-2023-22273 – ZDI-CAN-21307: Adobe RoboHelp Server OnPublishFile Directory Traversal Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2023-22273
15 Nov 2023 — Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to Remote Code Execution by an admin authenticated attacker. Exploitation of this issue does not require user interaction. Las versiones 11.4 y anteriores de Adobe RoboHelp Server se ven afectadas por una vulnerabilidad de limitación inadecuada de un nombre de ruta a un directorio restringido ("Path Traversal") que podría provocar la ... • https://helpx.adobe.com/security/products/robohelp-server/apsb23-53.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-22274 – ZDI-CAN-21305: Adobe RoboHelp Server UpdateCommandStream XML External Entity Processing Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-22274
15 Nov 2023 — Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction. Las versiones 11.4 y anteriores de Adobe RoboHelp Server se ven afectadas por una vulnerabilidad de restricción inadecuada de referencia de entidad externa XML ('XXE') que podría provocar la divulgación de información por parte de un... • https://helpx.adobe.com/security/products/robohelp-server/apsb23-53.html • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2023-22275 – ZDI-CAN-21306: Adobe RoboHelp Server GetNewUserId SQL Injection Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-22275
15 Nov 2023 — Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction. Las versiones 11.4 y anteriores de Adobe RoboHelp Server se ven afectadas por una neutralización inadecuada de elementos especiales utilizados en una vulnerabilidad de comando SQL ("inyección SQL") que podría p... • https://helpx.adobe.com/security/products/robohelp-server/apsb23-53.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2022-23201 – Adobe RoboHelp Reflected XSS could lead to Arbitrary code execution
https://notcve.org/view.php?id=CVE-2022-23201
15 Jul 2022 — Adobe RoboHelp versions 2020.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Adobe RoboHelp versiones 2020.0.7 (y anteriores), están afectadas por una vulnerabilidad de tipo Cross-Site Scripting (XSS) reflejado. Si un atacante es capaz de convencer a una víctima de que visite una URL que haga ... • https://helpx.adobe.com/security/products/robohelp/apsb22-10.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-30670 – Escalate Privileges to Server Admin - Robohelp Server
https://notcve.org/view.php?id=CVE-2022-30670
16 Jun 2022 — RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalation. An authenticated attacker could leverage this vulnerability to achieve full administrator privileges. Exploitation of this issue does not require user interaction. RoboHelp Server versiones anteriores a la actualización 3 de RHS 11, están afectadas por una vulnerabilidad de Autorización Inapropiada que podría conllevar a una elevación de privilegios. Un atac... • https://helpx.adobe.com/security/products/robohelp-server/apsb22-31.html • CWE-285: Improper Authorization •

CVE-2021-42727 – Adobe Bridge Buffer Overflow Arbitrary code execution
https://notcve.org/view.php?id=CVE-2021-42727
11 Nov 2021 — Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file in Bridge. Adobe Bridge versión 11.1.1 (y anteriores) está afectado por una vulnerabilidad de desbordamiento de pila debido a la gestión insegura de un archivo manipulado, lo que puede dar lugar a la ejecución de código a... • https://helpx.adobe.com/security/products/bridge/apsb21-94.html • CWE-787: Out-of-bounds Write •

CVE-2021-28588 – Adobe RoboHelp Server folderId Directory Traversal Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-28588
10 Jun 2021 — Adobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Adobe RoboHelp Server versiones 2019.0.9 (y anteriores), está afectada por una vulnerabilidad de Salto de Ruta cuando se analiza una petición HTTP POST diseñada. Un atacante aut... • https://www.zerodayinitiative.com/advisories/ZDI-21-660 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2021-21070 – Privilege Escalation Vulnerability in Adobe RoboHelp
https://notcve.org/view.php?id=CVE-2021-21070
19 Apr 2021 — Adobe Robohelp version 2020.0.3 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. An attacker with admin permissions to write to the file system could leverage this vulnerability to escalate privileges. La versión 2020.0.3 de Adobe Robohelp (y anteriores) se ve afectada por una vulnerabilidad en el elemento de ruta de búsqueda no controlada que podría conducir a una escalada de privilegios. Un atacante con permisos de administrador para e... • https://helpx.adobe.com/security/products/robohelp/apsb21-20.html • CWE-427: Uncontrolled Search Path Element •