midasolutions records
7 published records for vendor midasolutions.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 14.3%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
68This week | CVE-2020-15920Weaponized | There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with adminimidasolutions · eframework · CWE-78 | Critical9.8 | — | 98.2% | Jul 23, 2020 |
56Plan | CVE-2020-15922Proof of concept | There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrativemidasolutions · eframework · CWE-78 | Critical9.8 | — | 57.3% | Jul 23, 2020 |
44Plan | CVE-2020-15921Proof of concept | Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities,midasolutions · eframework · CWE-287 | Critical9.8 | — | 18.3% | Jul 23, 2020 |
31Monitor | CVE-2020-15923No exploit | Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.midasolutions · eframework · CWE-22 | High7.5 | — | 3.3% | Jul 23, 2020 |
31Monitor | CVE-2020-15924No exploit | There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure.midasolutions · eframework · CWE-89 | High7.5 | — | 1.9% | Jul 23, 2020 |
24Monitor | CVE-2020-15919No exploit | A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.midasolutions · eframework · CWE-79 | Medium6.1 | — | 0.9% | Jul 23, 2020 |
21Monitor | CVE-2020-15918No exploit | Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.midasolutions · eframework · CWE-79 | Medium5.4 | — | 0.6% | Jul 23, 2020 |
- CVE-2020-1592068This week
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with admini
CriticalCVSS 9.8WeaponizedEPSS 98%midasolutions · eframeworkJul 23, 2020
- CVE-2020-1592256Plan
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative
CriticalCVSS 9.8Proof of conceptEPSS 57%midasolutions · eframeworkJul 23, 2020
- CVE-2020-1592144Plan
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities,
CriticalCVSS 9.8Proof of conceptEPSS 18%midasolutions · eframeworkJul 23, 2020
- CVE-2020-1592331Monitor
Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.
HighCVSS 7.5No exploitEPSS 3%midasolutions · eframeworkJul 23, 2020
- CVE-2020-1592431Monitor
There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure.
HighCVSS 7.5No exploitEPSS 2%midasolutions · eframeworkJul 23, 2020
- CVE-2020-1591924Monitor
A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.
MediumCVSS 6.1No exploitEPSS 1%midasolutions · eframeworkJul 23, 2020
- CVE-2020-1591821Monitor
Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.
MediumCVSS 5.4No exploitEPSS 1%midasolutions · eframeworkJul 23, 2020