accela kayıtları
accela üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-20 Improper Input Validation1
- CWE-284 Improper Access Control1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2016-5661İstismar yok | Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated usersaccela · civic platform citizen access portal · CWE-284 | Yüksek8,8 | — | %2,6 | 15 Tem 2016 |
36İzleyin | CVE-2025-57644İstismar yok | Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature.accela · automation platform · CWE-20 | Kritik9,1 | — | %0,7 | 19 Eyl 2025 |
28İzleyin | CVE-2021-34369Kavram kanıtı | portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via aaccela · civic platform | Orta6,5 | — | %8,2 | 9 Haz 2021 |
27İzleyin | CVE-2021-34370Kavram kanıtı | Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS.accela · civic platform · CWE-79 | Orta6,1 | — | %10,0 | 9 Haz 2021 |
27İzleyin | CVE-2021-33904Kavram kanıtı | In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS.accela · civic platform · CWE-79 | Orta6,1 | — | %10,0 | 7 Haz 2021 |
24İzleyin | CVE-2016-5660İstismar yok | Cross-site scripting (XSS) vulnerability in AttachmentsList.aspx in Accela Civic Platform Citizen Access portal allows remote attackers to iaccela · civic platform · CWE-79 | Orta6,1 | — | %1,7 | 15 Tem 2016 |
- CVE-2016-566136İzleyin
Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users
YüksekCVSS 8,8İstismar yokEPSS %3accela · civic platform citizen access portal15 Tem 2016
- CVE-2025-5764436İzleyin
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature.
KritikCVSS 9,1İstismar yokEPSS %1accela · automation platform19 Eyl 2025
- CVE-2021-3436928İzleyin
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a
OrtaCVSS 6,5Kavram kanıtıEPSS %8accela · civic platform9 Haz 2021
- CVE-2021-3437027İzleyin
Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS.
OrtaCVSS 6,1Kavram kanıtıEPSS %10accela · civic platform9 Haz 2021
- CVE-2021-3390427İzleyin
In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS.
OrtaCVSS 6,1Kavram kanıtıEPSS %10accela · civic platform7 Haz 2021
- CVE-2016-566024İzleyin
Cross-site scripting (XSS) vulnerability in AttachmentsList.aspx in Accela Civic Platform Citizen Access portal allows remote attackers to i
OrtaCVSS 6,1İstismar yokEPSS %2accela · civic platform15 Tem 2016