esoftplanner records
6 published records for vendor esoftplanner.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-276 Incorrect Default Permissions1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2024-48530No exploit | An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (Doesoftplanner · esoft planner · CWE-770 | High7.5 | — | 0.6% | Nov 20, 2024 |
30Monitor | CVE-2024-48536No exploit | Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a cesoftplanner · esoft planner · CWE-79 | High7.5 | — | 0.5% | Nov 20, 2024 |
21Monitor | CVE-2024-48533No exploit | A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allowesoftplanner · esoft planner · CWE-276 | Medium5.3 | — | 0.4% | Nov 20, 2024 |
21Monitor | CVE-2024-48531No exploit | A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA allows attackers to eesoftplanner · esoft planner · CWE-79 | Medium5.4 | — | 0.4% | Nov 20, 2024 |
21Monitor | CVE-2024-48534No exploit | A reflected cross-site scripting (XSS) vulnerability on the Camp Details module of eSoft Planner 3.24.08271-USA allows attackers to execute esoftplanner · esoft planner · CWE-79 | Medium5.4 | — | 0.4% | Nov 20, 2024 |
21Monitor | CVE-2024-48535No exploit | A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary web scripts or HTML esoftplanner · esoft planner · CWE-79 | Medium5.4 | — | 0.3% | Nov 20, 2024 |
- CVE-2024-4853030Monitor
An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (Do
HighCVSS 7.5No exploitEPSS 1%esoftplanner · esoft plannerNov 20, 2024
- CVE-2024-4853630Monitor
Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a c
HighCVSS 7.5No exploitEPSS 0%esoftplanner · esoft plannerNov 20, 2024
- CVE-2024-4853321Monitor
A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allow
MediumCVSS 5.3No exploitEPSS 0%esoftplanner · esoft plannerNov 20, 2024
- CVE-2024-4853121Monitor
A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA allows attackers to e
MediumCVSS 5.4No exploitEPSS 0%esoftplanner · esoft plannerNov 20, 2024
- CVE-2024-4853421Monitor
A reflected cross-site scripting (XSS) vulnerability on the Camp Details module of eSoft Planner 3.24.08271-USA allows attackers to execute
MediumCVSS 5.4No exploitEPSS 0%esoftplanner · esoft plannerNov 20, 2024
- CVE-2024-4853521Monitor
A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary web scripts or HTML
MediumCVSS 5.4No exploitEPSS 0%esoftplanner · esoft plannerNov 20, 2024