open-audit records
6 published records for vendor open-audit.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2018-8979Proof of concept | Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.open-audit · open-audit · CWE-79 | High8.8 | — | 1.2% | Mar 25, 2018 |
28Monitor | CVE-2018-9137Proof of concept | Open-AudIT before 2.2 has CSV Injection.open-audit · open-audit · CWE-1236 | Medium6.8 | — | 2.7% | Apr 19, 2018 |
24Monitor | CVE-2018-8937No exploit | An issue was discovered in Open-AudIT Professional 2.1.open-audit · open-audit · CWE-601 | Medium6.1 | — | 0.7% | Mar 26, 2018 |
21Monitor | CVE-2018-8903Proof of concept | Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.open-audit · open-audit · CWE-79 | Medium5.4 | — | 1.6% | Mar 22, 2018 |
21Monitor | CVE-2018-9155Proof of concept | Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML viaopen-audit · open-audit · CWE-79 | Medium5.4 | — | 1.1% | Apr 12, 2018 |
21Monitor | CVE-2018-8978No exploit | Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI.open-audit · open-audit · CWE-79 | Medium5.4 | — | 0.5% | Mar 25, 2018 |
- CVE-2018-897935Monitor
Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.
HighCVSS 8.8Proof of conceptEPSS 1%open-audit · open-auditMar 25, 2018
- CVE-2018-913728Monitor
Open-AudIT before 2.2 has CSV Injection.
MediumCVSS 6.8Proof of conceptEPSS 3%open-audit · open-auditApr 19, 2018
- CVE-2018-893724Monitor
An issue was discovered in Open-AudIT Professional 2.1.
MediumCVSS 6.1No exploitEPSS 1%open-audit · open-auditMar 26, 2018
- CVE-2018-890321Monitor
Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.
MediumCVSS 5.4Proof of conceptEPSS 2%open-audit · open-auditMar 22, 2018
- CVE-2018-915521Monitor
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via
MediumCVSS 5.4Proof of conceptEPSS 1%open-audit · open-auditApr 12, 2018
- CVE-2018-897821Monitor
Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI.
MediumCVSS 5.4No exploitEPSS 1%open-audit · open-auditMar 25, 2018