Vulnerabilities (CVE)

Filtered by vendor Assaabloy Subscribe
Filtered by product Control Id Rhid
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-2125 1 Assaabloy 1 Control Id Rhid 2025-03-24 4.0 MEDIUM 4.3 MEDIUM
A vulnerability has been found in Control iD RH iD 25.2.25.0 and classified as problematic. This vulnerability affects unknown code of the file /v2/report.svc/comprovante_marcacao/?companyId=1 of the component PDF Document Handler. The manipulation of the argument nsr leads to improper control of resource identifiers. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-2043 1 Assaabloy 1 Control Id Rhid 2024-11-21 6.5 MEDIUM 6.3 MEDIUM
A vulnerability, which was classified as problematic, was found in Control iD RHiD 23.3.19.0. This affects an unknown part of the file /v2/customerdb/operator.svc/a of the component Edit Handler. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-225921 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.