Skip to content
Noroxi

unit4 records

11 published records for vendor unit4.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

11 records
  • Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack we

    CriticalCVSS 9.8No exploitEPSS 3%

    unit4 · teta webAug 2, 2017

  • UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    unit4 · tetaJul 17, 2022

  • Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operat

    HighCVSS 8.8No exploitEPSS 3%

    unit4 · mik.starlightAug 31, 2021

  • Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.

    HighCVSS 8.8No exploitEPSS 1%

    unit4 · mik.starlightAug 31, 2021

  • Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an

    HighCVSS 8.1No exploitEPSS 1%

    unit4 · financials by codaMar 20, 2024

  • CVE-2015-1173
    31Monitor

    Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode

    HighCVSS 7.5No exploitEPSS 2%

    unit4 · teta webSep 16, 2015

  • The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary

    MediumCVSS 6.5No exploitEPSS 1%

    unit4 · mik.starlightAug 31, 2021

  • Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.

    MediumCVSS 6.5No exploitEPSS 1%

    unit4 · enterprise resource planningJul 19, 2022

  • Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted

    MediumCVSS 6.1Proof of conceptEPSS 2%

    Mar 19, 2024

  • Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.

    MediumCVSS 5.5No exploitEPSS 0%

    unit4 · mik.starlightAug 31, 2021

  • CVE-2015-2082
    18Monitor

    Cross-site scripting (XSS) vulnerability in Login.aspx in UNIT4 Prosoft HRMS before 8.14.330.43 allows remote attackers to inject arbitrary

    MediumCVSS 4.3No exploitEPSS 2%

    unit4 · prosoft hrmsFeb 25, 2015