codekop records
4 published records for vendor codekop.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-306 Missing Authentication for Critical Function1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2023-36347Proof of concept | A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.codekop · codekop · CWE-306 | High7.5 | — | 34.1% | Jun 29, 2023 |
37Monitor | CVE-2023-36348Proof of concept | POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.codekop · codekop · CWE-862 | High8.8 | — | 6.4% | Jun 23, 2023 |
35Monitor | CVE-2023-36345No exploit | A Cross-Site Request Forgery (CSRF) in POS Codekop v2.0 allows attackers to escalate privileges.codekop · codekop · CWE-79 | High8.8 | — | 1.0% | Jun 23, 2023 |
26Monitor | CVE-2023-36346Proof of concept | POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php.codekop · codekop · CWE-79 | Medium6.1 | — | 5.3% | Jun 23, 2023 |
- CVE-2023-3634740Plan
A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.
HighCVSS 7.5Proof of conceptEPSS 34%codekop · codekopJun 29, 2023
- CVE-2023-3634837Monitor
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.
HighCVSS 8.8Proof of conceptEPSS 6%codekop · codekopJun 23, 2023
- CVE-2023-3634535Monitor
A Cross-Site Request Forgery (CSRF) in POS Codekop v2.0 allows attackers to escalate privileges.
HighCVSS 8.8No exploitEPSS 1%codekop · codekopJun 23, 2023
- CVE-2023-3634626Monitor
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php.
MediumCVSS 6.1Proof of conceptEPSS 5%codekop · codekopJun 23, 2023