Перейти к содержимому
Noroxi

Записи unit4

11 опубликованных записей вендора unit4.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

11 записей
  • CVE-2015-1174
    40В плане

    Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack we

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    unit4 · teta web2 авг. 2017 г.

  • CVE-2022-27434
    39Наблюдать

    UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the

    КритическаяCVSS 9,8Proof of conceptEPSS 1 %

    unit4 · teta17 июл. 2022 г.

  • CVE-2021-36231
    36Наблюдать

    Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operat

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    unit4 · mik.starlight31 авг. 2021 г.

  • CVE-2021-36232
    35Наблюдать

    Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    unit4 · mik.starlight31 авг. 2021 г.

  • CVE-2024-28735
    32Наблюдать

    Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    unit4 · financials by coda20 мар. 2024 г.

  • CVE-2015-1173
    31Наблюдать

    Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    unit4 · teta web16 сент. 2015 г.

  • CVE-2021-36233
    26Наблюдать

    The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    unit4 · mik.starlight31 авг. 2021 г.

  • CVE-2022-34001
    26Наблюдать

    Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    unit4 · enterprise resource planning19 июл. 2022 г.

  • CVE-2024-28734
    25Наблюдать

    Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted

    СредняяCVSS 6,1Proof of conceptEPSS 2 %

    19 мар. 2024 г.

  • CVE-2021-36234
    22Наблюдать

    Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    unit4 · mik.starlight31 авг. 2021 г.

  • CVE-2015-2082
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in Login.aspx in UNIT4 Prosoft HRMS before 8.14.330.43 allows remote attackers to inject arbitrary

    СредняяCVSS 4,3Эксплойта нетEPSS 2 %

    unit4 · prosoft hrms25 февр. 2015 г.