İçeriğe atla
Noroxi

bpcbt kayıtları

bpcbt üreticisine ait 11 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

11 kayıt
  • CVE-2022-38619
    39İzleyin

    SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups

    KritikCVSS 9,8İstismar yokEPSS %1

    bpcbt · smartvista front-end20 Eyl 2022

  • CVE-2022-38615
    35İzleyin

    SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and User

    YüksekCVSS 8,8İstismar yokEPSS %1

    bpcbt · smartvista front-end9 Eyl 2022

  • CVE-2022-38617
    35İzleyin

    SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/v

    YüksekCVSS 8,8İstismar yokEPSS %1

    bpcbt · smartvista19 Eyl 2022

  • CVE-2022-38616
    35İzleyin

    SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.

    YüksekCVSS 8,8İstismar yokEPSS %1

    bpcbt · smartvista front-end13 Eyl 2022

  • CVE-2022-38618
    35İzleyin

    SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id

    YüksekCVSS 8,8İstismar yokEPSS %1

    bpcbt · smartvista19 Eyl 2022

  • CVE-2018-15206
    35İzleyin

    BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.

    YüksekCVSS 8,8İstismar yokEPSS %1

    bpcbt · smartvista30 Nis 2019

  • CVE-2018-15208
    30İzleyin

    BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.

    YüksekCVSS 7,5İstismar yokEPSS %1

    bpcbt · smartvista30 Nis 2019

  • CVE-2022-38614
    30İzleyin

    An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files vi

    YüksekCVSS 7,5İstismar yokEPSS %1

    bpcbt · smartvista cardgen9 Eyl 2022

  • CVE-2018-15207
    28İzleyin

    BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to a

    YüksekCVSS 7,2İstismar yokEPSS %1

    bpcbt · smartvista30 Nis 2019

  • CVE-2022-38613
    26İzleyin

    A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.

    OrtaCVSS 6,5İstismar yokEPSS %1

    bpcbt · smartvista cardgen9 Eyl 2022

  • CVE-2022-35554
    24İzleyin

    Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an attacker to execute ja

    OrtaCVSS 6,1İstismar yokEPSS %1

    bpcbt · smartvista19 Ağu 2022