sitos records
6 published records for vendor sitos.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-269 Improper Privilege Management1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-15751No exploit | An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM fsitos · sitos six · CWE-434 | Critical9.8 | — | 4.5% | Oct 7, 2019 |
40Plan | CVE-2019-15746No exploit | SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands.sitos · sitos six · CWE-78 | Critical9.8 | — | 1.9% | Oct 7, 2019 |
39Monitor | CVE-2019-15748No exploit | SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected pages.sitos · sitos six · CWE-434 | Critical9.8 | — | 1.6% | Oct 7, 2019 |
35Monitor | CVE-2019-15747No exploit | SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Systemadministrator role sitos · sitos six · CWE-269 | High8.8 | — | 1.1% | Oct 7, 2019 |
26Monitor | CVE-2019-15749No exploit | SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with tsitos · sitos six · CWE-640 | Medium6.5 | — | 1.0% | Oct 7, 2019 |
24Monitor | CVE-2019-15750No exploit | A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web scsitos · sitos six · CWE-79 | Medium6.1 | — | 1.0% | Oct 7, 2019 |
- CVE-2019-1575140Plan
An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM f
CriticalCVSS 9.8No exploitEPSS 4%sitos · sitos sixOct 7, 2019
- CVE-2019-1574640Plan
SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands.
CriticalCVSS 9.8No exploitEPSS 2%sitos · sitos sixOct 7, 2019
- CVE-2019-1574839Monitor
SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected pages.
CriticalCVSS 9.8No exploitEPSS 2%sitos · sitos sixOct 7, 2019
- CVE-2019-1574735Monitor
SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Systemadministrator role
HighCVSS 8.8No exploitEPSS 1%sitos · sitos sixOct 7, 2019
- CVE-2019-1574926Monitor
SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with t
MediumCVSS 6.5No exploitEPSS 1%sitos · sitos sixOct 7, 2019
- CVE-2019-1575024Monitor
A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web sc
MediumCVSS 6.1No exploitEPSS 1%sitos · sitos sixOct 7, 2019