BigProf kayıtları
bigprof üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2020-35674İstismar yok | BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoinbigprof · online invoicing system · CWE-89 | Kritik9,8 | — | %1,1 | 28 Eyl 2022 |
35İzleyin | CVE-2020-35675İstismar yok | BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups.bigprof · online invoicing system · CWE-352 | Yüksek8,8 | — | %0,5 | 28 Eyl 2022 |
24İzleyin | CVE-2020-35676İstismar yok | BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration funcbigprof · online invoicing system · CWE-79 | Orta6,1 | — | %0,8 | 24 Ara 2020 |
24İzleyin | CVE-2020-6583İstismar yok | BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking.bigprof · online invoicing system · CWE-79 | Orta6,1 | — | %0,7 | 8 Oca 2020 |
21İzleyin | CVE-2021-21260İstismar yok | XSS in description fieldbigprof · online invoicing system · CWE-79 | Orta5,4 | — | %0,6 | 22 Oca 2021 |
21İzleyin | CVE-2018-18587İstismar yok | BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.bigprof · appgini · CWE-327 | Orta5,3 | — | %0,5 | 23 Eki 2018 |
21İzleyin | CVE-2023-6425İstismar yok | Cross-site Scripting vulnerability in BigProf productsbigprof · online clinic management system · CWE-79 | Orta5,4 | — | %0,4 | 30 Kas 2023 |
21İzleyin | CVE-2023-6435İstismar yok | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Orta5,4 | — | %0,4 | 30 Kas 2023 |
21İzleyin | CVE-2023-6422İstismar yok | Cross-site Scripting vulnerability in BigProf productsbigprof · online clinic management system · CWE-79 | Orta5,4 | — | %0,4 | 30 Kas 2023 |
21İzleyin | CVE-2023-6423İstismar yok | Cross-site Scripting vulnerability in BigProf productsbigprof · online clinic management system · CWE-79 | Orta5,4 | — | %0,4 | 30 Kas 2023 |
21İzleyin | CVE-2023-6424İstismar yok | Cross-site Scripting vulnerability in BigProf productsbigprof · online clinic management system · CWE-79 | Orta5,4 | — | %0,4 | 30 Kas 2023 |
21İzleyin | CVE-2023-6433İstismar yok | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Orta5,4 | — | %0,4 | 30 Kas 2023 |
21İzleyin | CVE-2023-6434İstismar yok | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Orta5,4 | — | %0,4 | 30 Kas 2023 |
21İzleyin | CVE-2023-6426İstismar yok | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Orta5,4 | — | %0,4 | 30 Kas 2023 |
21İzleyin | CVE-2023-6427İstismar yok | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Orta5,4 | — | %0,4 | 30 Kas 2023 |
21İzleyin | CVE-2023-6428İstismar yok | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Orta5,4 | — | %0,4 | 30 Kas 2023 |
21İzleyin | CVE-2023-6429İstismar yok | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Orta5,4 | — | %0,4 | 30 Kas 2023 |
21İzleyin | CVE-2023-6430İstismar yok | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Orta5,4 | — | %0,4 | 30 Kas 2023 |
21İzleyin | CVE-2023-6431İstismar yok | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Orta5,4 | — | %0,4 | 30 Kas 2023 |
21İzleyin | CVE-2023-6432İstismar yok | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Orta5,4 | — | %0,4 | 30 Kas 2023 |
19İzleyin | CVE-2020-35677İstismar yok | BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEdibigprof · online invoicing system · CWE-79 | Orta4,8 | — | %0,3 | 24 Ara 2020 |
17İzleyin | CVE-2021-27839İstismar yok | A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions subigprof · online invoicing system · CWE-1236 | Orta4,4 | — | %0,7 | 3 Mar 2021 |
- CVE-2020-3567439İzleyin
BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoin
KritikCVSS 9,8İstismar yokEPSS %1bigprof · online invoicing system28 Eyl 2022
- CVE-2020-3567535İzleyin
BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups.
YüksekCVSS 8,8İstismar yokEPSS %0bigprof · online invoicing system28 Eyl 2022
- CVE-2020-3567624İzleyin
BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration func
OrtaCVSS 6,1İstismar yokEPSS %1bigprof · online invoicing system24 Ara 2020
- CVE-2020-658324İzleyin
BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking.
OrtaCVSS 6,1İstismar yokEPSS %1bigprof · online invoicing system8 Oca 2020
- CVE-2021-2126021İzleyin
XSS in description field
OrtaCVSS 5,4İstismar yokEPSS %1bigprof · online invoicing system22 Oca 2021
- CVE-2018-1858721İzleyin
BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.
OrtaCVSS 5,3İstismar yokEPSS %1bigprof · appgini23 Eki 2018
- CVE-2023-642521İzleyin
Cross-site Scripting vulnerability in BigProf products
OrtaCVSS 5,4İstismar yokEPSS %0bigprof · online clinic management system30 Kas 2023
- CVE-2023-643521İzleyin
Cross-site Scripting vulnerability in BigProf products
OrtaCVSS 5,4İstismar yokEPSS %0bigprof · online invoicing system30 Kas 2023
- CVE-2023-642221İzleyin
Cross-site Scripting vulnerability in BigProf products
OrtaCVSS 5,4İstismar yokEPSS %0bigprof · online clinic management system30 Kas 2023
- CVE-2023-642321İzleyin
Cross-site Scripting vulnerability in BigProf products
OrtaCVSS 5,4İstismar yokEPSS %0bigprof · online clinic management system30 Kas 2023
- CVE-2023-642421İzleyin
Cross-site Scripting vulnerability in BigProf products
OrtaCVSS 5,4İstismar yokEPSS %0bigprof · online clinic management system30 Kas 2023
- CVE-2023-643321İzleyin
Cross-site Scripting vulnerability in BigProf products
OrtaCVSS 5,4İstismar yokEPSS %0bigprof · online invoicing system30 Kas 2023
- CVE-2023-643421İzleyin
Cross-site Scripting vulnerability in BigProf products
OrtaCVSS 5,4İstismar yokEPSS %0bigprof · online invoicing system30 Kas 2023
- CVE-2023-642621İzleyin
Cross-site Scripting vulnerability in BigProf products
OrtaCVSS 5,4İstismar yokEPSS %0bigprof · online invoicing system30 Kas 2023
- CVE-2023-642721İzleyin
Cross-site Scripting vulnerability in BigProf products
OrtaCVSS 5,4İstismar yokEPSS %0bigprof · online invoicing system30 Kas 2023
- CVE-2023-642821İzleyin
Cross-site Scripting vulnerability in BigProf products
OrtaCVSS 5,4İstismar yokEPSS %0bigprof · online invoicing system30 Kas 2023
- CVE-2023-642921İzleyin
Cross-site Scripting vulnerability in BigProf products
OrtaCVSS 5,4İstismar yokEPSS %0bigprof · online invoicing system30 Kas 2023
- CVE-2023-643021İzleyin
Cross-site Scripting vulnerability in BigProf products
OrtaCVSS 5,4İstismar yokEPSS %0bigprof · online invoicing system30 Kas 2023
- CVE-2023-643121İzleyin
Cross-site Scripting vulnerability in BigProf products
OrtaCVSS 5,4İstismar yokEPSS %0bigprof · online invoicing system30 Kas 2023
- CVE-2023-643221İzleyin
Cross-site Scripting vulnerability in BigProf products
OrtaCVSS 5,4İstismar yokEPSS %0bigprof · online invoicing system30 Kas 2023
- CVE-2020-3567719İzleyin
BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEdi
OrtaCVSS 4,8İstismar yokEPSS %0bigprof · online invoicing system24 Ara 2020
- CVE-2021-2783917İzleyin
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions su
OrtaCVSS 4,4İstismar yokEPSS %1bigprof · online invoicing system3 Mar 2021