Skip to content
Noroxi

eramba records

11 published records for vendor eramba.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 9.1%
Pre-auth RCE
0
With a fix record
9.1%
Median publish → KEV
No record has entered KEV

All records

11 records
  • An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path

    HighCVSS 8.8WeaponizedEPSS 53%

    eramba · erambaAug 2, 2023

  • eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).

    CriticalCVSS 9.8No exploitEPSS 1%

    eramba · erambaSep 3, 2020

  • A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in t

    MediumCVSS 6.5Proof of conceptEPSS 0%

    eramba · erambaJan 13, 2026

  • CVE-2018-7894
    24Monitor

    Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search Parameter)

    MediumCVSS 6.1No exploitEPSS 1%

    eramba · erambaMar 9, 2018

  • CVE-2018-7741
    24Monitor

    Eramba e1.0.6.033 has Reflected XSS in the Date Filter via the created parameter to the /crons URI.

    MediumCVSS 6.1No exploitEPSS 1%

    eramba · erambaMar 7, 2018

  • CVE-2018-7996
    24Monitor

    Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    eramba · erambaMar 9, 2018

  • CVE-2018-7997
    24Monitor

    Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with a CSV file polluted

    MediumCVSS 6.1No exploitEPSS 1%

    eramba · erambaMar 9, 2018

  • eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object.

    MediumCVSS 5.4No exploitEPSS 1%

    eramba · erambaSep 3, 2020

  • A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute arbitrary we

    MediumCVSS 5.4No exploitEPSS 1%

    eramba · erambaNov 14, 2022

  • A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated att

    MediumCVSS 5.4No exploitEPSS 0%

    May 15, 2024

  • eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated users.

    MediumCVSS 4.3No exploitEPSS 1%

    eramba · erambaNov 2, 2020