Записи unit4
11 опубликованных записей вендора unit4.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-287 Improper Authentication1
- CWE-384 Session Fixation1
- CWE-502 Deserialization of Untrusted Data1
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-611 Improper Restriction of XML External Entity Reference1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2015-1174Эксплойта нет | Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack weunit4 · teta web · CWE-384 | Критическая9,8 | — | 2,9 % | 2 авг. 2017 г. |
39Наблюдать | CVE-2022-27434Proof of concept | UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in theunit4 · teta · CWE-89 | Критическая9,8 | — | 1,4 % | 17 июл. 2022 г. |
36Наблюдать | CVE-2021-36231Эксплойта нет | Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operatunit4 · mik.starlight · CWE-502 | Высокая8,8 | — | 2,6 % | 31 авг. 2021 г. |
35Наблюдать | CVE-2021-36232Эксплойта нет | Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.unit4 · mik.starlight · CWE-862 | Высокая8,8 | — | 1,1 % | 31 авг. 2021 г. |
32Наблюдать | CVE-2024-28735Эксплойта нет | Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows anunit4 · financials by coda · CWE-287 | Высокая8,1 | — | 0,7 % | 20 мар. 2024 г. |
31Наблюдать | CVE-2015-1173Эксплойта нет | Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger modeunit4 · teta web · CWE-284 | Высокая7,5 | — | 2,2 % | 16 сент. 2015 г. |
26Наблюдать | CVE-2021-36233Эксплойта нет | The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary unit4 · mik.starlight · CWE-552 | Средняя6,5 | — | 1,0 % | 31 авг. 2021 г. |
26Наблюдать | CVE-2022-34001Эксплойта нет | Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.unit4 · enterprise resource planning · CWE-611 | Средняя6,5 | — | 0,8 % | 19 июл. 2022 г. |
25Наблюдать | CVE-2024-28734Proof of concept | Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted CWE-79 | Средняя6,1 | — | 1,8 % | 19 мар. 2024 г. |
22Наблюдать | CVE-2021-36234Эксплойта нет | Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.unit4 · mik.starlight · CWE-798 | Средняя5,5 | — | 0,3 % | 31 авг. 2021 г. |
18Наблюдать | CVE-2015-2082Эксплойта нет | Cross-site scripting (XSS) vulnerability in Login.aspx in UNIT4 Prosoft HRMS before 8.14.330.43 allows remote attackers to inject arbitrary unit4 · prosoft hrms · CWE-79 | Средняя4,3 | — | 1,9 % | 25 февр. 2015 г. |
- CVE-2015-117440В плане
Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack we
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %unit4 · teta web2 авг. 2017 г.
- CVE-2022-2743439Наблюдать
UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the
КритическаяCVSS 9,8Proof of conceptEPSS 1 %unit4 · teta17 июл. 2022 г.
- CVE-2021-3623136Наблюдать
Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operat
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %unit4 · mik.starlight31 авг. 2021 г.
- CVE-2021-3623235Наблюдать
Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %unit4 · mik.starlight31 авг. 2021 г.
- CVE-2024-2873532Наблюдать
Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %unit4 · financials by coda20 мар. 2024 г.
- CVE-2015-117331Наблюдать
Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %unit4 · teta web16 сент. 2015 г.
- CVE-2021-3623326Наблюдать
The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary
СредняяCVSS 6,5Эксплойта нетEPSS 1 %unit4 · mik.starlight31 авг. 2021 г.
- CVE-2022-3400126Наблюдать
Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %unit4 · enterprise resource planning19 июл. 2022 г.
- CVE-2024-2873425Наблюдать
Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted
СредняяCVSS 6,1Proof of conceptEPSS 2 %19 мар. 2024 г.
- CVE-2021-3623422Наблюдать
Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %unit4 · mik.starlight31 авг. 2021 г.
- CVE-2015-208218Наблюдать
Cross-site scripting (XSS) vulnerability in Login.aspx in UNIT4 Prosoft HRMS before 8.14.330.43 allows remote attackers to inject arbitrary
СредняяCVSS 4,3Эксплойта нетEPSS 2 %unit4 · prosoft hrms25 февр. 2015 г.