Skip to content
Noroxi

midasolutions records

7 published records for vendor midasolutions.

All records

7 records
  • CVE-2020-15920
    68This week

    There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with admini

    CriticalCVSS 9.8WeaponizedEPSS 98%

    midasolutions · eframeworkJul 23, 2020

  • There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative

    CriticalCVSS 9.8Proof of conceptEPSS 57%

    midasolutions · eframeworkJul 23, 2020

  • Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities,

    CriticalCVSS 9.8Proof of conceptEPSS 18%

    midasolutions · eframeworkJul 23, 2020

  • Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.

    HighCVSS 7.5No exploitEPSS 3%

    midasolutions · eframeworkJul 23, 2020

  • There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure.

    HighCVSS 7.5No exploitEPSS 2%

    midasolutions · eframeworkJul 23, 2020

  • A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.

    MediumCVSS 6.1No exploitEPSS 1%

    midasolutions · eframeworkJul 23, 2020

  • Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.

    MediumCVSS 5.4No exploitEPSS 1%

    midasolutions · eframeworkJul 23, 2020