Vulnerabilities (CVE)

Filtered by vendor Os4ed Subscribe
Total 65 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-27408 1 Os4ed 1 Opensis 2024-11-21 5.0 MEDIUM 7.5 HIGH
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
CVE-2020-13383 1 Os4ed 1 Opensis 2024-11-21 5.0 MEDIUM 7.5 HIGH
openSIS through 7.4 allows Directory Traversal.
CVE-2020-13382 1 Os4ed 1 Opensis 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
openSIS through 7.4 has Incorrect Access Control.
CVE-2020-13381 1 Os4ed 1 Opensis 2024-11-21 7.5 HIGH 9.8 CRITICAL
openSIS through 7.4 allows SQL Injection.
CVE-2020-13380 1 Os4ed 1 Opensis 2024-11-21 7.5 HIGH 9.8 CRITICAL
openSIS before 7.4 allows SQL Injection.