openpsa2 records
2 published records for vendor openpsa2.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-1000525No exploit | openpsa contains a PHP Object Injection vulnerability in Form data passed as GET request variables that can result in Possible information dopenpsa2 · openpsa · CWE-502 | Critical9.8 | — | 4.1% | Jun 26, 2018 |
31Monitor | CVE-2018-1000526No exploit | Openpsa contains a XML Injection vulnerability in RSS file upload feature that can result in Remote denial of service.openpsa2 · openpsa · CWE-91 | High7.5 | — | 2.1% | Jun 26, 2018 |
- CVE-2018-100052540Plan
openpsa contains a PHP Object Injection vulnerability in Form data passed as GET request variables that can result in Possible information d
CriticalCVSS 9.8No exploitEPSS 4%openpsa2 · openpsaJun 26, 2018
- CVE-2018-100052631Monitor
Openpsa contains a XML Injection vulnerability in RSS file upload feature that can result in Remote denial of service.
HighCVSS 7.5No exploitEPSS 2%openpsa2 · openpsaJun 26, 2018