inxedu records
7 published records for vendor inxedu.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2020-35326No exploit | SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0inxedu · inxedu · CWE-89 | Critical9.8 | — | 13.6% | Jan 18, 2023 |
40Plan | CVE-2019-7684No exploit | inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file.inxedu · inxedu · CWE-434 | Critical9.8 | — | 2.1% | Feb 9, 2019 |
39Monitor | CVE-2020-35430No exploit | SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsystinxedu · inxedu · CWE-89 | Critical9.8 | — | 1.1% | Apr 29, 2021 |
39Monitor | CVE-2024-35570No exploit | An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows attackers to executeinxedu · inxedu · CWE-434 | Critical9.8 | — | 0.9% | May 23, 2024 |
39Monitor | CVE-2020-21152No exploit | SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunctioinxedu · inxedu · CWE-89 | Critical9.8 | — | 0.8% | Jan 20, 2023 |
39Monitor | CVE-2024-35079No exploit | An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading inxedu · inxedu · CWE-434 | Critical9.8 | — | 0.6% | May 23, 2024 |
39Monitor | CVE-2024-35080No exploit | An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a craftinxedu · inxedu · CWE-434 | Critical9.8 | — | 0.6% | May 23, 2024 |
- CVE-2020-3532643Plan
SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0
CriticalCVSS 9.8No exploitEPSS 14%inxedu · inxeduJan 18, 2023
- CVE-2019-768440Plan
inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file.
CriticalCVSS 9.8No exploitEPSS 2%inxedu · inxeduFeb 9, 2019
- CVE-2020-3543039Monitor
SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsyst
CriticalCVSS 9.8No exploitEPSS 1%inxedu · inxeduApr 29, 2021
- CVE-2024-3557039Monitor
An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows attackers to execute
CriticalCVSS 9.8No exploitEPSS 1%inxedu · inxeduMay 23, 2024
- CVE-2020-2115239Monitor
SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunctio
CriticalCVSS 9.8No exploitEPSS 1%inxedu · inxeduJan 20, 2023
- CVE-2024-3507939Monitor
An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading
CriticalCVSS 9.8No exploitEPSS 1%inxedu · inxeduMay 23, 2024
- CVE-2024-3508039Monitor
An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a craft
CriticalCVSS 9.8No exploitEPSS 1%inxedu · inxeduMay 23, 2024