oroinc kayıtları
oroinc üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %92,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-284 Improper Access Control4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2022-41951İstismar yok | OroPlatform vulnerable to path traversal during temporary file manipulationsoroinc · oroplatform · CWE-22 | Kritik9,8 | — | %0,9 | 27 Kas 2023 |
35İzleyin | CVE-2021-43852İstismar yok | JavaScript Prototype Pollution in oro/platformoroinc · oroplatform · CWE-74 | Yüksek8,8 | — | %1,1 | 4 Oca 2022 |
24İzleyin | CVE-2024-50677Kavram kanıtı | A cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted poroinc · oroplatform · CWE-79 | Orta6,1 | — | %0,6 | 6 Ara 2024 |
23İzleyin | CVE-2023-32065İstismar yok | OroCommerce get-totals-for-checkout API endpoint returns unwanted dataoroinc · orocommerce · CWE-284 | Orta5,8 | — | %0,5 | 28 Kas 2023 |
21İzleyin | CVE-2022-31037İstismar yok | OroCommerce vulnerable to Cross-site Scripting via Shipping rule editing pageoroinc · orocommerce · CWE-79 | Orta5,4 | — | %0,4 | 18 Eki 2022 |
21İzleyin | CVE-2021-39198İstismar yok | The disqualify lead action may be executed without CSRF token checkoroinc · client relationship management · CWE-352 | Orta5,4 | — | %0,3 | 19 Kas 2021 |
20İzleyin | CVE-2023-32063İstismar yok | OroCRMCallBundle has incorrect call view page visibilityoroinc · client relationship management · CWE-284 | Orta5,0 | — | %0,5 | 28 Kas 2023 |
19İzleyin | CVE-2021-41236İstismar yok | XSS vulnerability in oro/platformoroinc · oroplatform · CWE-79 | Orta4,8 | — | %0,7 | 4 Oca 2022 |
19İzleyin | CVE-2022-35950İstismar yok | OroCommerce Cross-site Scripting vulnerability in add note dialog of Shopping List line itemoroinc · orocommerce · CWE-79 | Orta4,8 | — | %0,4 | 9 Eki 2023 |
17İzleyin | CVE-2023-32062İstismar yok | OroCalendarBundle has incorrect system calendar events visibilityoroinc · oroplatform · CWE-284 | Orta4,3 | — | %0,5 | 27 Kas 2023 |
17İzleyin | CVE-2023-32064İstismar yok | OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibilityoroinc · orocommerce · CWE-284 | Orta4,3 | — | %0,5 | 28 Kas 2023 |
17İzleyin | CVE-2023-45824İstismar yok | OroPlatform's pinned entity creation form shows pages of other usersoroinc · oroplatform · CWE-200 | Orta4,3 | — | %0,4 | 25 Mar 2024 |
17İzleyin | CVE-2023-48296İstismar yok | OroPlatform's storefront user can access history and most viewed data from matching back-office user with the same IDoroinc · oroplatform · CWE-200 | Orta4,3 | — | %0,4 | 25 Mar 2024 |
- CVE-2022-4195139İzleyin
OroPlatform vulnerable to path traversal during temporary file manipulations
KritikCVSS 9,8İstismar yokEPSS %1oroinc · oroplatform27 Kas 2023
- CVE-2021-4385235İzleyin
JavaScript Prototype Pollution in oro/platform
YüksekCVSS 8,8İstismar yokEPSS %1oroinc · oroplatform4 Oca 2022
- CVE-2024-5067724İzleyin
A cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted p
OrtaCVSS 6,1Kavram kanıtıEPSS %1oroinc · oroplatform6 Ara 2024
- CVE-2023-3206523İzleyin
OroCommerce get-totals-for-checkout API endpoint returns unwanted data
OrtaCVSS 5,8İstismar yokEPSS %0oroinc · orocommerce28 Kas 2023
- CVE-2022-3103721İzleyin
OroCommerce vulnerable to Cross-site Scripting via Shipping rule editing page
OrtaCVSS 5,4İstismar yokEPSS %0oroinc · orocommerce18 Eki 2022
- CVE-2021-3919821İzleyin
The disqualify lead action may be executed without CSRF token check
OrtaCVSS 5,4İstismar yokEPSS %0oroinc · client relationship management19 Kas 2021
- CVE-2023-3206320İzleyin
OroCRMCallBundle has incorrect call view page visibility
OrtaCVSS 5,0İstismar yokEPSS %1oroinc · client relationship management28 Kas 2023
- CVE-2021-4123619İzleyin
XSS vulnerability in oro/platform
OrtaCVSS 4,8İstismar yokEPSS %1oroinc · oroplatform4 Oca 2022
- CVE-2022-3595019İzleyin
OroCommerce Cross-site Scripting vulnerability in add note dialog of Shopping List line item
OrtaCVSS 4,8İstismar yokEPSS %0oroinc · orocommerce9 Eki 2023
- CVE-2023-3206217İzleyin
OroCalendarBundle has incorrect system calendar events visibility
OrtaCVSS 4,3İstismar yokEPSS %1oroinc · oroplatform27 Kas 2023
- CVE-2023-3206417İzleyin
OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility
OrtaCVSS 4,3İstismar yokEPSS %0oroinc · orocommerce28 Kas 2023
- CVE-2023-4582417İzleyin
OroPlatform's pinned entity creation form shows pages of other users
OrtaCVSS 4,3İstismar yokEPSS %0oroinc · oroplatform25 Mar 2024
- CVE-2023-4829617İzleyin
OroPlatform's storefront user can access history and most viewed data from matching back-office user with the same ID
OrtaCVSS 4,3İstismar yokEPSS %0oroinc · oroplatform25 Mar 2024