Skip to content
Noroxi

open-audit records

6 published records for vendor open-audit.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

6 records
  • CVE-2018-8979
    35Monitor

    Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.

    HighCVSS 8.8Proof of conceptEPSS 1%

    open-audit · open-auditMar 25, 2018

  • CVE-2018-9137
    28Monitor

    Open-AudIT before 2.2 has CSV Injection.

    MediumCVSS 6.8Proof of conceptEPSS 3%

    open-audit · open-auditApr 19, 2018

  • CVE-2018-8937
    24Monitor

    An issue was discovered in Open-AudIT Professional 2.1.

    MediumCVSS 6.1No exploitEPSS 1%

    open-audit · open-auditMar 26, 2018

  • CVE-2018-8903
    21Monitor

    Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.

    MediumCVSS 5.4Proof of conceptEPSS 2%

    open-audit · open-auditMar 22, 2018

  • CVE-2018-9155
    21Monitor

    Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via

    MediumCVSS 5.4Proof of conceptEPSS 1%

    open-audit · open-auditApr 12, 2018

  • CVE-2018-8978
    21Monitor

    Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI.

    MediumCVSS 5.4No exploitEPSS 1%

    open-audit · open-auditMar 25, 2018