citsmart records
2 published records for vendor citsmart.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2020-35775Proof of concept | CITSmart before 9.1.2.23 allows LDAP Injection.citsmart · citsmart · CWE-74 | Critical9.8 | — | 13.3% | Feb 15, 2021 |
37Monitor | CVE-2021-28142Proof of concept | CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."citsmart · citsmart · CWE-89 | High8.8 | — | 5.8% | Apr 6, 2021 |
- CVE-2020-3577543Plan
CITSmart before 9.1.2.23 allows LDAP Injection.
CriticalCVSS 9.8Proof of conceptEPSS 13%citsmart · citsmartFeb 15, 2021
- CVE-2021-2814237Monitor
CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."
HighCVSS 8.8Proof of conceptEPSS 6%citsmart · citsmartApr 6, 2021