İçeriğe atla
Noroxi

GestSup kayıtları

gestsup üreticisine ait 8 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%50
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

8 kayıt
  • CVE-2021-31646
    39İzleyin

    Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote).

    KritikCVSS 9,8İstismar yokEPSS %1

    gestsup · gestsup26 Nis 2021

  • CVE-2026-22194
    35İzleyin

    GestSup <= 3.2.60 CSRF Allows Privileged Actions

    YüksekCVSS 8,9İstismar yokEPSS %0

    gestsup · gestsup9 Oca 2026

  • CVE-2026-22197
    30İzleyin

    GestSup < 3.2.60 Multiple SQL Injections in Asset List

    YüksekCVSS 7,5İstismar yokEPSS %0

    gestsup · gestsup9 Oca 2026

  • CVE-2026-22195
    30İzleyin

    GestSup < 3.2.60 SQL Injection in Search Bar

    YüksekCVSS 7,7İstismar yokEPSS %0

    gestsup · gestsup9 Oca 2026

  • CVE-2026-22196
    30İzleyin

    GestSup < 3.2.60 SQL Injection in Ticket Creation

    YüksekCVSS 7,7İstismar yokEPSS %0

    gestsup · gestsup9 Oca 2026

  • CVE-2023-52059
    21İzleyin

    A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted payloa

    OrtaCVSS 5,4İstismar yokEPSS %0

    gestsup · gestsup12 Şub 2024

  • CVE-2026-22198
    20İzleyin

    GestSup < 3.2.60 Stored XSS in API Error Logs

    OrtaCVSS 5,1İstismar yokEPSS %0

    gestsup · gestsup9 Oca 2026

  • CVE-2023-52060
    17İzleyin

    A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.

    OrtaCVSS 4,3İstismar yokEPSS %0

    gestsup · gestsup12 Şub 2024