Skip to content
Noroxi

minical records

5 published records for vendor minical.

All records

5 records
  • Minical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code.

    HighCVSS 8.8Proof of conceptEPSS 1%

    minical · minicalJun 5, 2023

  • An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data parameter.

    HighCVSS 8.8Proof of conceptEPSS 1%

    minical · minicalOct 30, 2023

  • CVE-2023-3307
    35Monitor

    miniCal sql injection

    HighCVSS 8.8No exploitEPSS 1%

    minical · minicalJun 18, 2023

  • Minical 1.0.0 is vulnerable to Cross Site Request Forgery (CSRF) via minical/public/application/controllers/settings/company.php.

    MediumCVSS 6.5Proof of conceptEPSS 0%

    minical · minicalJun 5, 2023

  • Minical 1.0.0 is vulnerable to Cross Site Scripting (XSS).

    MediumCVSS 5.4Proof of conceptEPSS 1%

    minical · minicalJun 5, 2023