netadmin records
3 published records for vendor netadmin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-203 Observable Discrepancy1
- CWE-284 Improper Access Control1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2024-48955Proof of concept | Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, theCWE-284 | High8.1 | — | 0.6% | Oct 29, 2024 |
26Monitor | CVE-2024-9513Proof of concept | Netadmin Software NetAdmin IAM HTTP POST Request ReturnUserQuestionsFilled information exposurenetadmin · netadmin iam · CWE-203 | Medium6.3 | — | 1.7% | Oct 4, 2024 |
21Monitor | CVE-2024-51026Proof of concept | The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is poCWE-79 | Medium5.4 | — | 0.4% | Nov 11, 2024 |
- CVE-2024-4895532Monitor
Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the
HighCVSS 8.1Proof of conceptEPSS 1%Oct 29, 2024
- CVE-2024-951326Monitor
Netadmin Software NetAdmin IAM HTTP POST Request ReturnUserQuestionsFilled information exposure
MediumCVSS 6.3Proof of conceptEPSS 2%netadmin · netadmin iamOct 4, 2024
- CVE-2024-5102621Monitor
The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is po
MediumCVSS 5.4Proof of conceptEPSS 0%Nov 11, 2024