Записи inxedu
7 опубликованных записей вендора inxedu.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2020-35326Эксплойта нет | SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0inxedu · inxedu · CWE-89 | Критическая9,8 | — | 13,6 % | 18 янв. 2023 г. |
40В плане | CVE-2019-7684Эксплойта нет | inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file.inxedu · inxedu · CWE-434 | Критическая9,8 | — | 2,1 % | 9 февр. 2019 г. |
39Наблюдать | CVE-2020-35430Эксплойта нет | SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsystinxedu · inxedu · CWE-89 | Критическая9,8 | — | 1,1 % | 29 апр. 2021 г. |
39Наблюдать | CVE-2024-35570Эксплойта нет | An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows attackers to executeinxedu · inxedu · CWE-434 | Критическая9,8 | — | 0,9 % | 23 мая 2024 г. |
39Наблюдать | CVE-2020-21152Эксплойта нет | SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunctioinxedu · inxedu · CWE-89 | Критическая9,8 | — | 0,8 % | 20 янв. 2023 г. |
39Наблюдать | CVE-2024-35079Эксплойта нет | An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading inxedu · inxedu · CWE-434 | Критическая9,8 | — | 0,6 % | 23 мая 2024 г. |
39Наблюдать | CVE-2024-35080Эксплойта нет | An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a craftinxedu · inxedu · CWE-434 | Критическая9,8 | — | 0,6 % | 23 мая 2024 г. |
- CVE-2020-3532643В плане
SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0
КритическаяCVSS 9,8Эксплойта нетEPSS 14 %inxedu · inxedu18 янв. 2023 г.
- CVE-2019-768440В плане
inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %inxedu · inxedu9 февр. 2019 г.
- CVE-2020-3543039Наблюдать
SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsyst
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %inxedu · inxedu29 апр. 2021 г.
- CVE-2024-3557039Наблюдать
An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows attackers to execute
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %inxedu · inxedu23 мая 2024 г.
- CVE-2020-2115239Наблюдать
SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunctio
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %inxedu · inxedu20 янв. 2023 г.
- CVE-2024-3507939Наблюдать
An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %inxedu · inxedu23 мая 2024 г.
- CVE-2024-3508039Наблюдать
An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a craft
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %inxedu · inxedu23 мая 2024 г.