İçeriğe atla
Noroxi

syspass kayıtları

syspass üreticisine ait 7 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%14,3
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

7 kayıt
  • CVE-2025-25477
    32İzleyin

    A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be

    YüksekCVSS 8,1İstismar yokEPSS %0

    syspass · syspass27 Şub 2025

  • CVE-2017-5999
    30İzleyin

    An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers.

    YüksekCVSS 7,5İstismar yokEPSS %1

    syspass · syspass6 Mar 2017

  • CVE-2025-25478
    26İzleyin

    The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames.

    OrtaCVSS 6,5İstismar yokEPSS %0

    syspass · syspass28 Şub 2025

  • CVE-2017-9306
    24İzleyin

    inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" su

    OrtaCVSS 6,1İstismar yokEPSS %1

    syspass · syspass31 May 2017

  • CVE-2024-42904
    24İzleyin

    A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafte

    OrtaCVSS 6,1İstismar yokEPSS %0

    syspass · syspass3 Eyl 2024

  • CVE-2022-4930
    21İzleyin

    nuxsmin sysPass URL cross site scripting

    OrtaCVSS 5,4İstismar yokEPSS %1

    syspass · syspass6 Mar 2023

  • CVE-2025-25476
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Jav

    OrtaCVSS 5,4İstismar yokEPSS %0

    syspass · syspass28 Şub 2025