Перейти к содержимому
Noroxi

Записи inxedu

7 опубликованных записей вендора inxedu.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
4
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 19
  2. 21
  3. 23
  4. 24

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

7 записей
  • CVE-2020-35326
    43В плане

    SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0

    КритическаяCVSS 9,8Эксплойта нетEPSS 14 %

    inxedu · inxedu18 янв. 2023 г.

  • CVE-2019-7684
    40В плане

    inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    inxedu · inxedu9 февр. 2019 г.

  • CVE-2020-35430
    39Наблюдать

    SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsyst

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    inxedu · inxedu29 апр. 2021 г.

  • CVE-2024-35570
    39Наблюдать

    An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows attackers to execute

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    inxedu · inxedu23 мая 2024 г.

  • CVE-2020-21152
    39Наблюдать

    SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunctio

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    inxedu · inxedu20 янв. 2023 г.

  • CVE-2024-35079
    39Наблюдать

    An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    inxedu · inxedu23 мая 2024 г.

  • CVE-2024-35080
    39Наблюдать

    An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a craft

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    inxedu · inxedu23 мая 2024 г.