unit4 records
11 published records for vendor unit4.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-287 Improper Authentication1
- CWE-384 Session Fixation1
- CWE-502 Deserialization of Untrusted Data1
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-611 Improper Restriction of XML External Entity Reference1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2015-1174No exploit | Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack weunit4 · teta web · CWE-384 | Critical9.8 | — | 2.9% | Aug 2, 2017 |
39Monitor | CVE-2022-27434Proof of concept | UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in theunit4 · teta · CWE-89 | Critical9.8 | — | 1.4% | Jul 17, 2022 |
36Monitor | CVE-2021-36231No exploit | Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operatunit4 · mik.starlight · CWE-502 | High8.8 | — | 2.6% | Aug 31, 2021 |
35Monitor | CVE-2021-36232No exploit | Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.unit4 · mik.starlight · CWE-862 | High8.8 | — | 1.1% | Aug 31, 2021 |
32Monitor | CVE-2024-28735No exploit | Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows anunit4 · financials by coda · CWE-287 | High8.1 | — | 0.7% | Mar 20, 2024 |
31Monitor | CVE-2015-1173No exploit | Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger modeunit4 · teta web · CWE-284 | High7.5 | — | 2.2% | Sep 16, 2015 |
26Monitor | CVE-2021-36233No exploit | The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary unit4 · mik.starlight · CWE-552 | Medium6.5 | — | 1.0% | Aug 31, 2021 |
26Monitor | CVE-2022-34001No exploit | Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.unit4 · enterprise resource planning · CWE-611 | Medium6.5 | — | 0.8% | Jul 19, 2022 |
25Monitor | CVE-2024-28734Proof of concept | Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted CWE-79 | Medium6.1 | — | 1.8% | Mar 19, 2024 |
22Monitor | CVE-2021-36234No exploit | Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.unit4 · mik.starlight · CWE-798 | Medium5.5 | — | 0.3% | Aug 31, 2021 |
18Monitor | CVE-2015-2082No exploit | Cross-site scripting (XSS) vulnerability in Login.aspx in UNIT4 Prosoft HRMS before 8.14.330.43 allows remote attackers to inject arbitrary unit4 · prosoft hrms · CWE-79 | Medium4.3 | — | 1.9% | Feb 25, 2015 |
- CVE-2015-117440Plan
Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack we
CriticalCVSS 9.8No exploitEPSS 3%unit4 · teta webAug 2, 2017
- CVE-2022-2743439Monitor
UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the
CriticalCVSS 9.8Proof of conceptEPSS 1%unit4 · tetaJul 17, 2022
- CVE-2021-3623136Monitor
Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operat
HighCVSS 8.8No exploitEPSS 3%unit4 · mik.starlightAug 31, 2021
- CVE-2021-3623235Monitor
Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.
HighCVSS 8.8No exploitEPSS 1%unit4 · mik.starlightAug 31, 2021
- CVE-2024-2873532Monitor
Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an
HighCVSS 8.1No exploitEPSS 1%unit4 · financials by codaMar 20, 2024
- CVE-2015-117331Monitor
Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode
HighCVSS 7.5No exploitEPSS 2%unit4 · teta webSep 16, 2015
- CVE-2021-3623326Monitor
The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary
MediumCVSS 6.5No exploitEPSS 1%unit4 · mik.starlightAug 31, 2021
- CVE-2022-3400126Monitor
Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.
MediumCVSS 6.5No exploitEPSS 1%unit4 · enterprise resource planningJul 19, 2022
- CVE-2024-2873425Monitor
Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted
MediumCVSS 6.1Proof of conceptEPSS 2%Mar 19, 2024
- CVE-2021-3623422Monitor
Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.
MediumCVSS 5.5No exploitEPSS 0%unit4 · mik.starlightAug 31, 2021
- CVE-2015-208218Monitor
Cross-site scripting (XSS) vulnerability in Login.aspx in UNIT4 Prosoft HRMS before 8.14.330.43 allows remote attackers to inject arbitrary
MediumCVSS 4.3No exploitEPSS 2%unit4 · prosoft hrmsFeb 25, 2015