Skip to content
Noroxi

Webbax records

8 published records for vendor webbax.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

8 records
  • SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privileges via the Super News

    CriticalCVSS 9.8No exploitEPSS 1%

    Apr 30, 2024

  • PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postProcess().

    CriticalCVSS 9.8No exploitEPSS 1%

    webbax · postfinanceJun 14, 2023

  • Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download.php.

    HighCVSS 7.5Proof of conceptEPSS 6%

    webbax · winbizpaymentJun 12, 2023

  • Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest to download personal

    HighCVSS 7.5No exploitEPSS 1%

    webbax · myinventoryMay 30, 2023

  • Prestashop customexporter <= 1.7.20 is vulnerable to Incorrect Access Control via modules/customexporter/downloads/download.php.

    HighCVSS 7.5No exploitEPSS 1%

    webbax · customexporterMay 19, 2023

  • Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php.

    HighCVSS 7.5No exploitEPSS 0%

    webbax · salesboosterMay 30, 2023

  • An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attack

    HighCVSS 7.5No exploitEPSS 0%

    webbax · super newsletterMar 3, 2024

  • CVE-2023-3031
    19Monitor

    Prestahop module King-Avis - Path traversal

    MediumCVSS 4.9No exploitEPSS 1%

    webbax · king-avisJun 2, 2023