Skip to content
Noroxi

sparkdevnetwork records

3 published records for vendor sparkdevnetwork.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 20
  2. 21

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

All records

3 records
  • Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application.

    CriticalCVSS 9.8No exploitEPSS 4%

    sparkdevnetwork · rock rmsJan 7, 2021

  • Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller.

    CriticalCVSS 9.8No exploitEPSS 3%

    sparkdevnetwork · rock rmsMar 20, 2020

  • Rock RMS version before 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile update feature.

    CriticalCVSS 9.8No exploitEPSS 2%

    sparkdevnetwork · rock rmsJan 7, 2021