Skip to content
Noroxi

sendio records

3 published records for vendor sendio.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 17

Bar: total · dark part: CISA KEV.

Attack profile

All records

3 records
  • Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remote attacker to read

    HighCVSS 7.5No exploitEPSS 1%

    sendio · sendioJul 27, 2017

  • CVE-2014-0999
    22Monitor

    Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hij

    MediumCVSS 5.0Proof of conceptEPSS 7%

    sendio · sendioJun 2, 2015

  • CVE-2014-8391
    18Monitor

    The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive info

    MediumCVSS 4.0Proof of conceptEPSS 5%

    sendio · sendioJun 2, 2015