open-school kayıtları
open-school üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2019-14754İstismar yok | Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter.open-school · open-school · CWE-89 | Kritik9,8 | — | %1,5 | 8 Ağu 2019 |
30İzleyin | CVE-2009-4208Kavram kanıtı | SQL injection vulnerability in the os_news module in Open-school (OS) 1.0 allows remote attackers to execute arbitrary SQL commands via the open-school · open-school · CWE-89 | Yüksek7,5 | — | %0,9 | 4 Ara 2009 |
29İzleyin | CVE-2019-14696Kavram kanıtı | Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.open-school · open-school · CWE-79 | Orta6,1 | — | %15,7 | 6 Ağu 2019 |
26İzleyin | CVE-2014-9127İstismar yok | Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenticated users to open-school · open-school · CWE-200 | Orta6,5 | — | %1,4 | 8 Şub 2020 |
24İzleyin | CVE-2014-9126İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Open-School Community Edition 2.2 allow remote attackers to inject arbitrary web scriopen-school · open-school · CWE-79 | Orta6,1 | — | %1,1 | 8 Şub 2020 |
- CVE-2019-1475439İzleyin
Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter.
KritikCVSS 9,8İstismar yokEPSS %2open-school · open-school8 Ağu 2019
- CVE-2009-420830İzleyin
SQL injection vulnerability in the os_news module in Open-school (OS) 1.0 allows remote attackers to execute arbitrary SQL commands via the
YüksekCVSS 7,5Kavram kanıtıEPSS %1open-school · open-school4 Ara 2009
- CVE-2019-1469629İzleyin
Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %16open-school · open-school6 Ağu 2019
- CVE-2014-912726İzleyin
Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenticated users to
OrtaCVSS 6,5İstismar yokEPSS %1open-school · open-school8 Şub 2020
- CVE-2014-912624İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Open-School Community Edition 2.2 allow remote attackers to inject arbitrary web scri
OrtaCVSS 6,1İstismar yokEPSS %1open-school · open-school8 Şub 2020