Записи Exrick
10 опубликованных записей вендора exrick.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-284 Improper Access Control2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2024-24112Proof of concept | xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.exrick · xmall · CWE-89 | Критическая9,8 | — | 3,3 % | 5 февр. 2024 г. |
39Наблюдать | CVE-2025-28399Эксплойта нет | An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controlexrick · xmall · CWE-269 | Критическая9,8 | — | 0,6 % | 15 апр. 2025 г. |
39Наблюдать | CVE-2025-45612Эксплойта нет | Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.exrick · xmall · CWE-284 | Критическая9,8 | — | 0,5 % | 5 мая 2025 г. |
32Наблюдать | CVE-2023-36331Эксплойта нет | Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via maexrick · xmall · CWE-639 | Высокая8,2 | — | 0,2 % | 12 янв. 2026 г. |
24Наблюдать | CVE-2021-43432Эксплойта нет | A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.exrick · xmall · CWE-79 | Средняя6,1 | — | 0,8 % | 7 апр. 2022 г. |
24Наблюдать | CVE-2025-65540Эксплойта нет | Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data.exrick · xmall · CWE-79 | Средняя6,1 | — | 0,2 % | 29 нояб. 2025 г. |
22Наблюдать | CVE-2025-8525Эксплойта нет | Exrick xboot Spring Boot Admin/Spring Actuator information disclosureexrick · xboot · CWE-200 | Средняя5,5 | — | 0,4 % | 4 авг. 2025 г. |
11Наблюдать | CVE-2025-8528Эксплойта нет | Exrick xboot getMenuList sensitive information in a cookieexrick · xboot · CWE-312 | Низкая2,9 | — | 0,3 % | 4 авг. 2025 г. |
8Наблюдать | CVE-2025-8526Эксплойта нет | Exrick xboot UploadController.java upload unrestricted uploadexrick · xboot · CWE-284 | Низкая2,1 | — | 0,3 % | 4 авг. 2025 г. |
8Наблюдать | CVE-2025-8527Эксплойта нет | Exrick xboot Swagger SecurityController.java server-side request forgeryexrick · xboot · CWE-918 | Низкая2,1 | — | 0,3 % | 4 авг. 2025 г. |
- CVE-2024-2411240В плане
xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.
КритическаяCVSS 9,8Proof of conceptEPSS 3 %exrick · xmall5 февр. 2024 г.
- CVE-2025-2839939Наблюдать
An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Control
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %exrick · xmall15 апр. 2025 г.
- CVE-2025-4561239Наблюдать
Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %exrick · xmall5 мая 2025 г.
- CVE-2023-3633132Наблюдать
Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via ma
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %exrick · xmall12 янв. 2026 г.
- CVE-2021-4343224Наблюдать
A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %exrick · xmall7 апр. 2022 г.
- CVE-2025-6554024Наблюдать
Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %exrick · xmall29 нояб. 2025 г.
- CVE-2025-852522Наблюдать
Exrick xboot Spring Boot Admin/Spring Actuator information disclosure
СредняяCVSS 5,5Эксплойта нетEPSS 0 %exrick · xboot4 авг. 2025 г.
- CVE-2025-852811Наблюдать
Exrick xboot getMenuList sensitive information in a cookie
НизкаяCVSS 2,9Эксплойта нетEPSS 0 %exrick · xboot4 авг. 2025 г.
- CVE-2025-85268Наблюдать
Exrick xboot UploadController.java upload unrestricted upload
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %exrick · xboot4 авг. 2025 г.
- CVE-2025-85278Наблюдать
Exrick xboot Swagger SecurityController.java server-side request forgery
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %exrick · xboot4 авг. 2025 г.