İçeriğe atla
Noroxi

BigProf kayıtları

bigprof üreticisine ait 22 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

22 kayıt
  • CVE-2020-35674
    39İzleyin

    BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoin

    KritikCVSS 9,8İstismar yokEPSS %1

    bigprof · online invoicing system28 Eyl 2022

  • CVE-2020-35675
    35İzleyin

    BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups.

    YüksekCVSS 8,8İstismar yokEPSS %0

    bigprof · online invoicing system28 Eyl 2022

  • CVE-2020-35676
    24İzleyin

    BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration func

    OrtaCVSS 6,1İstismar yokEPSS %1

    bigprof · online invoicing system24 Ara 2020

  • CVE-2020-6583
    24İzleyin

    BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking.

    OrtaCVSS 6,1İstismar yokEPSS %1

    bigprof · online invoicing system8 Oca 2020

  • CVE-2021-21260
    21İzleyin

    XSS in description field

    OrtaCVSS 5,4İstismar yokEPSS %1

    bigprof · online invoicing system22 Oca 2021

  • CVE-2018-18587
    21İzleyin

    BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.

    OrtaCVSS 5,3İstismar yokEPSS %1

    bigprof · appgini23 Eki 2018

  • CVE-2023-6425
    21İzleyin

    Cross-site Scripting vulnerability in BigProf products

    OrtaCVSS 5,4İstismar yokEPSS %0

    bigprof · online clinic management system30 Kas 2023

  • CVE-2023-6435
    21İzleyin

    Cross-site Scripting vulnerability in BigProf products

    OrtaCVSS 5,4İstismar yokEPSS %0

    bigprof · online invoicing system30 Kas 2023

  • CVE-2023-6422
    21İzleyin

    Cross-site Scripting vulnerability in BigProf products

    OrtaCVSS 5,4İstismar yokEPSS %0

    bigprof · online clinic management system30 Kas 2023

  • CVE-2023-6423
    21İzleyin

    Cross-site Scripting vulnerability in BigProf products

    OrtaCVSS 5,4İstismar yokEPSS %0

    bigprof · online clinic management system30 Kas 2023

  • CVE-2023-6424
    21İzleyin

    Cross-site Scripting vulnerability in BigProf products

    OrtaCVSS 5,4İstismar yokEPSS %0

    bigprof · online clinic management system30 Kas 2023

  • CVE-2023-6433
    21İzleyin

    Cross-site Scripting vulnerability in BigProf products

    OrtaCVSS 5,4İstismar yokEPSS %0

    bigprof · online invoicing system30 Kas 2023

  • CVE-2023-6434
    21İzleyin

    Cross-site Scripting vulnerability in BigProf products

    OrtaCVSS 5,4İstismar yokEPSS %0

    bigprof · online invoicing system30 Kas 2023

  • CVE-2023-6426
    21İzleyin

    Cross-site Scripting vulnerability in BigProf products

    OrtaCVSS 5,4İstismar yokEPSS %0

    bigprof · online invoicing system30 Kas 2023

  • CVE-2023-6427
    21İzleyin

    Cross-site Scripting vulnerability in BigProf products

    OrtaCVSS 5,4İstismar yokEPSS %0

    bigprof · online invoicing system30 Kas 2023

  • CVE-2023-6428
    21İzleyin

    Cross-site Scripting vulnerability in BigProf products

    OrtaCVSS 5,4İstismar yokEPSS %0

    bigprof · online invoicing system30 Kas 2023

  • CVE-2023-6429
    21İzleyin

    Cross-site Scripting vulnerability in BigProf products

    OrtaCVSS 5,4İstismar yokEPSS %0

    bigprof · online invoicing system30 Kas 2023

  • CVE-2023-6430
    21İzleyin

    Cross-site Scripting vulnerability in BigProf products

    OrtaCVSS 5,4İstismar yokEPSS %0

    bigprof · online invoicing system30 Kas 2023

  • CVE-2023-6431
    21İzleyin

    Cross-site Scripting vulnerability in BigProf products

    OrtaCVSS 5,4İstismar yokEPSS %0

    bigprof · online invoicing system30 Kas 2023

  • CVE-2023-6432
    21İzleyin

    Cross-site Scripting vulnerability in BigProf products

    OrtaCVSS 5,4İstismar yokEPSS %0

    bigprof · online invoicing system30 Kas 2023

  • CVE-2020-35677
    19İzleyin

    BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEdi

    OrtaCVSS 4,8İstismar yokEPSS %0

    bigprof · online invoicing system24 Ara 2020

  • CVE-2021-27839
    17İzleyin

    A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions su

    OrtaCVSS 4,4İstismar yokEPSS %1

    bigprof · online invoicing system3 Mar 2021