Skip to content
Noroxi

codekop records

4 published records for vendor codekop.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

4 records
  • A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.

    HighCVSS 7.5Proof of conceptEPSS 34%

    codekop · codekopJun 29, 2023

  • POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.

    HighCVSS 8.8Proof of conceptEPSS 6%

    codekop · codekopJun 23, 2023

  • A Cross-Site Request Forgery (CSRF) in POS Codekop v2.0 allows attackers to escalate privileges.

    HighCVSS 8.8No exploitEPSS 1%

    codekop · codekopJun 23, 2023

  • POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php.

    MediumCVSS 6.1Proof of conceptEPSS 5%

    codekop · codekopJun 23, 2023