Skip to content
Noroxi

sitos records

6 published records for vendor sitos.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

6 records
  • An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM f

    CriticalCVSS 9.8No exploitEPSS 4%

    sitos · sitos sixOct 7, 2019

  • SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands.

    CriticalCVSS 9.8No exploitEPSS 2%

    sitos · sitos sixOct 7, 2019

  • SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected pages.

    CriticalCVSS 9.8No exploitEPSS 2%

    sitos · sitos sixOct 7, 2019

  • SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Systemadministrator role

    HighCVSS 8.8No exploitEPSS 1%

    sitos · sitos sixOct 7, 2019

  • SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with t

    MediumCVSS 6.5No exploitEPSS 1%

    sitos · sitos sixOct 7, 2019

  • A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web sc

    MediumCVSS 6.1No exploitEPSS 1%

    sitos · sitos sixOct 7, 2019