Skip to content
Noroxi

bpcbt records

11 published records for vendor bpcbt.

All records

11 records
  • SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups

    CriticalCVSS 9.8No exploitEPSS 1%

    bpcbt · smartvista front-endSep 20, 2022

  • SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and User

    HighCVSS 8.8No exploitEPSS 1%

    bpcbt · smartvista front-endSep 9, 2022

  • SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/v

    HighCVSS 8.8No exploitEPSS 1%

    bpcbt · smartvistaSep 19, 2022

  • SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.

    HighCVSS 8.8No exploitEPSS 1%

    bpcbt · smartvista front-endSep 13, 2022

  • SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id

    HighCVSS 8.8No exploitEPSS 1%

    bpcbt · smartvistaSep 19, 2022

  • BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.

    HighCVSS 8.8No exploitEPSS 1%

    bpcbt · smartvistaApr 30, 2019

  • BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.

    HighCVSS 7.5No exploitEPSS 1%

    bpcbt · smartvistaApr 30, 2019

  • An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files vi

    HighCVSS 7.5No exploitEPSS 1%

    bpcbt · smartvista cardgenSep 9, 2022

  • BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to a

    HighCVSS 7.2No exploitEPSS 1%

    bpcbt · smartvistaApr 30, 2019

  • A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.

    MediumCVSS 6.5No exploitEPSS 1%

    bpcbt · smartvista cardgenSep 9, 2022

  • Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an attacker to execute ja

    MediumCVSS 6.1No exploitEPSS 1%

    bpcbt · smartvistaAug 19, 2022