Skip to content
Noroxi

syspass records

7 published records for vendor syspass.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
14.3%
Median publish → KEV
No record has entered KEV

All records

7 records
  • A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be

    HighCVSS 8.1No exploitEPSS 0%

    syspass · syspassFeb 27, 2025

  • CVE-2017-5999
    30Monitor

    An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers.

    HighCVSS 7.5No exploitEPSS 1%

    syspass · syspassMar 6, 2017

  • The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames.

    MediumCVSS 6.5No exploitEPSS 0%

    syspass · syspassFeb 28, 2025

  • CVE-2017-9306
    24Monitor

    inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" su

    MediumCVSS 6.1No exploitEPSS 1%

    syspass · syspassMay 31, 2017

  • A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafte

    MediumCVSS 6.1No exploitEPSS 0%

    syspass · syspassSep 3, 2024

  • CVE-2022-4930
    21Monitor

    nuxsmin sysPass URL cross site scripting

    MediumCVSS 5.4No exploitEPSS 1%

    syspass · syspassMar 6, 2023

  • A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Jav

    MediumCVSS 5.4No exploitEPSS 0%

    syspass · syspassFeb 28, 2025