Skip to content
Noroxi

inxedu records

7 published records for vendor inxedu.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
4
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 19
  2. 21
  3. 23
  4. 24

Bar: total · dark part: CISA KEV.

All records

7 records
  • SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0

    CriticalCVSS 9.8No exploitEPSS 14%

    inxedu · inxeduJan 18, 2023

  • inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file.

    CriticalCVSS 9.8No exploitEPSS 2%

    inxedu · inxeduFeb 9, 2019

  • SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsyst

    CriticalCVSS 9.8No exploitEPSS 1%

    inxedu · inxeduApr 29, 2021

  • An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows attackers to execute

    CriticalCVSS 9.8No exploitEPSS 1%

    inxedu · inxeduMay 23, 2024

  • SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunctio

    CriticalCVSS 9.8No exploitEPSS 1%

    inxedu · inxeduJan 20, 2023

  • An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading

    CriticalCVSS 9.8No exploitEPSS 1%

    inxedu · inxeduMay 23, 2024

  • An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a craft

    CriticalCVSS 9.8No exploitEPSS 1%

    inxedu · inxeduMay 23, 2024