Записи totemo
9 опубликованных записей вендора totemo.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-284 Improper Access Control1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-639 Authorization Bypass Through User-Controlled Key1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2018-6563Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers tototemo · encryption gateway · CWE-352 | Высокая8,8 | — | 2,3 % | 20 июн. 2018 г. |
30Наблюдать | CVE-2018-6562Эксплойта нет | totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption keytotemo · totemomail encryption gateway · CWE-345 | Высокая7,5 | — | 0,7 % | 18 мая 2018 г. |
24Наблюдать | CVE-2018-15511Эксплойта нет | Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to injtotemo · totemomail · CWE-79 | Средняя6,1 | — | 1,0 % | 30 авг. 2019 г. |
24Наблюдать | CVE-2018-15512Эксплойта нет | Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to injtotemo · totemomail · CWE-79 | Средняя6,1 | — | 1,0 % | 30 авг. 2019 г. |
24Наблюдать | CVE-2018-15510Эксплойта нет | Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrtotemo · totemomail · CWE-79 | Средняя6,1 | — | 0,6 % | 30 авг. 2019 г. |
24Наблюдать | CVE-2024-28063Эксплойта нет | Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.totemo · totemomail · CWE-79 | Средняя6,1 | — | 0,3 % | 18 мая 2024 г. |
21Наблюдать | CVE-2018-15513Эксплойта нет | Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor rototemo · totemomail · CWE-284 | Средняя5,3 | — | 1,0 % | 30 авг. 2019 г. |
21Наблюдать | CVE-2019-17189Эксплойта нет | totemodata 3.0.0_b936 has XSS via a folder name.totemo · totemodata · CWE-79 | Средняя5,4 | — | 0,8 % | 22 окт. 2019 г. |
21Наблюдать | CVE-2020-7918Эксплойта нет | An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail foldertotemo · totemomail · CWE-639 | Средняя5,4 | — | 0,7 % | 27 мар. 2020 г. |
- CVE-2018-656336Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %totemo · encryption gateway20 июн. 2018 г.
- CVE-2018-656230Наблюдать
totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption key
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %totemo · totemomail encryption gateway18 мая 2018 г.
- CVE-2018-1551124Наблюдать
Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inj
СредняяCVSS 6,1Эксплойта нетEPSS 1 %totemo · totemomail30 авг. 2019 г.
- CVE-2018-1551224Наблюдать
Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inj
СредняяCVSS 6,1Эксплойта нетEPSS 1 %totemo · totemomail30 авг. 2019 г.
- CVE-2018-1551024Наблюдать
Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitr
СредняяCVSS 6,1Эксплойта нетEPSS 1 %totemo · totemomail30 авг. 2019 г.
- CVE-2024-2806324Наблюдать
Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %totemo · totemomail18 мая 2024 г.
- CVE-2018-1551321Наблюдать
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor ro
СредняяCVSS 5,3Эксплойта нетEPSS 1 %totemo · totemomail30 авг. 2019 г.
- CVE-2019-1718921Наблюдать
totemodata 3.0.0_b936 has XSS via a folder name.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %totemo · totemodata22 окт. 2019 г.
- CVE-2020-791821Наблюдать
An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder
СредняяCVSS 5,4Эксплойта нетEPSS 1 %totemo · totemomail27 мар. 2020 г.