Записи schben
3 опубликованных записей вендора schben.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
3 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
38Наблюдать | CVE-2019-14347Proof of concept | Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account schben · adive · CWE-425 | Высокая8,8 | — | 9,3 % | 6 авг. 2019 г. |
36Наблюдать | CVE-2019-14346Proof of concept | Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.schben · adive · CWE-352 | Высокая8,8 | — | 2,7 % | 6 авг. 2019 г. |
19Наблюдать | CVE-2019-14987Эксплойта нет | Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions.schben · framework · CWE-79 | Средняя4,8 | — | 0,6 % | 13 авг. 2019 г. |
- CVE-2019-1434738Наблюдать
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account
ВысокаяCVSS 8,8Proof of conceptEPSS 9 %schben · adive6 авг. 2019 г.
- CVE-2019-1434636Наблюдать
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %schben · adive6 авг. 2019 г.
- CVE-2019-1498719Наблюдать
Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %schben · framework13 авг. 2019 г.