egain kayıtları
egain üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-13976İstismar yok | eGain Chat 15.0.3 allows unrestricted file upload.egain · chat · CWE-434 | Kritik9,8 | — | %1,7 | 4 Eyl 2019 |
30İzleyin | CVE-2019-17123İstismar yok | The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as egain · mail · CWE-74 | Yüksek7,5 | — | %1,0 | 13 Ara 2019 |
24İzleyin | CVE-2020-15948İstismar yok | eGain Chat 15.5.5 allows XSS via the Name (aka full_name) field.egain · chat · CWE-79 | Orta6,1 | — | %0,9 | 30 Tem 2021 |
24İzleyin | CVE-2019-13975İstismar yok | eGain Chat 15.0.3 allows HTML Injection.egain · chat · CWE-79 | Orta6,1 | — | %0,9 | 4 Eyl 2019 |
- CVE-2019-1397640Planlayın
eGain Chat 15.0.3 allows unrestricted file upload.
KritikCVSS 9,8İstismar yokEPSS %2egain · chat4 Eyl 2019
- CVE-2019-1712330İzleyin
The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as
YüksekCVSS 7,5İstismar yokEPSS %1egain · mail13 Ara 2019
- CVE-2020-1594824İzleyin
eGain Chat 15.5.5 allows XSS via the Name (aka full_name) field.
OrtaCVSS 6,1İstismar yokEPSS %1egain · chat30 Tem 2021
- CVE-2019-1397524İzleyin
eGain Chat 15.0.3 allows HTML Injection.
OrtaCVSS 6,1İstismar yokEPSS %1egain · chat4 Eyl 2019