Записи BigProf
22 опубликованных записей вендора bigprof.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2020-35674Эксплойта нет | BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoinbigprof · online invoicing system · CWE-89 | Критическая9,8 | — | 1,1 % | 28 сент. 2022 г. |
35Наблюдать | CVE-2020-35675Эксплойта нет | BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups.bigprof · online invoicing system · CWE-352 | Высокая8,8 | — | 0,5 % | 28 сент. 2022 г. |
24Наблюдать | CVE-2020-35676Эксплойта нет | BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration funcbigprof · online invoicing system · CWE-79 | Средняя6,1 | — | 0,8 % | 24 дек. 2020 г. |
24Наблюдать | CVE-2020-6583Эксплойта нет | BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking.bigprof · online invoicing system · CWE-79 | Средняя6,1 | — | 0,7 % | 8 янв. 2020 г. |
21Наблюдать | CVE-2021-21260Эксплойта нет | XSS in description fieldbigprof · online invoicing system · CWE-79 | Средняя5,4 | — | 0,6 % | 22 янв. 2021 г. |
21Наблюдать | CVE-2018-18587Эксплойта нет | BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.bigprof · appgini · CWE-327 | Средняя5,3 | — | 0,5 % | 23 окт. 2018 г. |
21Наблюдать | CVE-2023-6425Эксплойта нет | Cross-site Scripting vulnerability in BigProf productsbigprof · online clinic management system · CWE-79 | Средняя5,4 | — | 0,4 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2023-6435Эксплойта нет | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Средняя5,4 | — | 0,4 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2023-6422Эксплойта нет | Cross-site Scripting vulnerability in BigProf productsbigprof · online clinic management system · CWE-79 | Средняя5,4 | — | 0,4 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2023-6423Эксплойта нет | Cross-site Scripting vulnerability in BigProf productsbigprof · online clinic management system · CWE-79 | Средняя5,4 | — | 0,4 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2023-6424Эксплойта нет | Cross-site Scripting vulnerability in BigProf productsbigprof · online clinic management system · CWE-79 | Средняя5,4 | — | 0,4 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2023-6433Эксплойта нет | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Средняя5,4 | — | 0,4 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2023-6434Эксплойта нет | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Средняя5,4 | — | 0,4 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2023-6426Эксплойта нет | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Средняя5,4 | — | 0,4 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2023-6427Эксплойта нет | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Средняя5,4 | — | 0,4 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2023-6428Эксплойта нет | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Средняя5,4 | — | 0,4 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2023-6429Эксплойта нет | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Средняя5,4 | — | 0,4 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2023-6430Эксплойта нет | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Средняя5,4 | — | 0,4 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2023-6431Эксплойта нет | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Средняя5,4 | — | 0,4 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2023-6432Эксплойта нет | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Средняя5,4 | — | 0,4 % | 30 нояб. 2023 г. |
19Наблюдать | CVE-2020-35677Эксплойта нет | BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEdibigprof · online invoicing system · CWE-79 | Средняя4,8 | — | 0,3 % | 24 дек. 2020 г. |
17Наблюдать | CVE-2021-27839Эксплойта нет | A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions subigprof · online invoicing system · CWE-1236 | Средняя4,4 | — | 0,7 % | 3 мар. 2021 г. |
- CVE-2020-3567439Наблюдать
BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoin
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bigprof · online invoicing system28 сент. 2022 г.
- CVE-2020-3567535Наблюдать
BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %bigprof · online invoicing system28 сент. 2022 г.
- CVE-2020-3567624Наблюдать
BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration func
СредняяCVSS 6,1Эксплойта нетEPSS 1 %bigprof · online invoicing system24 дек. 2020 г.
- CVE-2020-658324Наблюдать
BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %bigprof · online invoicing system8 янв. 2020 г.
- CVE-2021-2126021Наблюдать
XSS in description field
СредняяCVSS 5,4Эксплойта нетEPSS 1 %bigprof · online invoicing system22 янв. 2021 г.
- CVE-2018-1858721Наблюдать
BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %bigprof · appgini23 окт. 2018 г.
- CVE-2023-642521Наблюдать
Cross-site Scripting vulnerability in BigProf products
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bigprof · online clinic management system30 нояб. 2023 г.
- CVE-2023-643521Наблюдать
Cross-site Scripting vulnerability in BigProf products
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bigprof · online invoicing system30 нояб. 2023 г.
- CVE-2023-642221Наблюдать
Cross-site Scripting vulnerability in BigProf products
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bigprof · online clinic management system30 нояб. 2023 г.
- CVE-2023-642321Наблюдать
Cross-site Scripting vulnerability in BigProf products
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bigprof · online clinic management system30 нояб. 2023 г.
- CVE-2023-642421Наблюдать
Cross-site Scripting vulnerability in BigProf products
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bigprof · online clinic management system30 нояб. 2023 г.
- CVE-2023-643321Наблюдать
Cross-site Scripting vulnerability in BigProf products
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bigprof · online invoicing system30 нояб. 2023 г.
- CVE-2023-643421Наблюдать
Cross-site Scripting vulnerability in BigProf products
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bigprof · online invoicing system30 нояб. 2023 г.
- CVE-2023-642621Наблюдать
Cross-site Scripting vulnerability in BigProf products
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bigprof · online invoicing system30 нояб. 2023 г.
- CVE-2023-642721Наблюдать
Cross-site Scripting vulnerability in BigProf products
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bigprof · online invoicing system30 нояб. 2023 г.
- CVE-2023-642821Наблюдать
Cross-site Scripting vulnerability in BigProf products
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bigprof · online invoicing system30 нояб. 2023 г.
- CVE-2023-642921Наблюдать
Cross-site Scripting vulnerability in BigProf products
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bigprof · online invoicing system30 нояб. 2023 г.
- CVE-2023-643021Наблюдать
Cross-site Scripting vulnerability in BigProf products
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bigprof · online invoicing system30 нояб. 2023 г.
- CVE-2023-643121Наблюдать
Cross-site Scripting vulnerability in BigProf products
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bigprof · online invoicing system30 нояб. 2023 г.
- CVE-2023-643221Наблюдать
Cross-site Scripting vulnerability in BigProf products
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bigprof · online invoicing system30 нояб. 2023 г.
- CVE-2020-3567719Наблюдать
BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEdi
СредняяCVSS 4,8Эксплойта нетEPSS 0 %bigprof · online invoicing system24 дек. 2020 г.
- CVE-2021-2783917Наблюдать
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions su
СредняяCVSS 4,4Эксплойта нетEPSS 1 %bigprof · online invoicing system3 мар. 2021 г.