Cipplanner

Cipace

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.97%
  • Veröffentlicht 06.04.2020 22:15:13
  • Zuletzt bearbeitet 21.11.2024 04:58:12

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and obtain the upload folder path that includes the hostname in a UNC path.

Exploit
  • EPSS 0.71%
  • Veröffentlicht 06.04.2020 22:15:13
  • Zuletzt bearbeitet 21.11.2024 04:58:11

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that causes a stack error to be shown providing the full file path.

Exploit
  • EPSS 1.11%
  • Veröffentlicht 06.04.2020 22:15:13
  • Zuletzt bearbeitet 21.11.2024 04:58:11

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to send emails from a customer trusted email address.

Exploit
  • EPSS 0.97%
  • Veröffentlicht 06.04.2020 22:15:13
  • Zuletzt bearbeitet 21.11.2024 04:58:11

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and get the columns of a specific table within the CIP database.

Exploit
  • EPSS 0.88%
  • Veröffentlicht 06.04.2020 22:15:13
  • Zuletzt bearbeitet 21.11.2024 04:58:11

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and obtain the full application path along with the customer name.

Exploit
  • EPSS 0.65%
  • Veröffentlicht 06.04.2020 22:15:13
  • Zuletzt bearbeitet 21.11.2024 04:58:11

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to HealthPage.aspx and obtain the internal server name.

Exploit
  • EPSS 0.92%
  • Veröffentlicht 06.04.2020 22:15:13
  • Zuletzt bearbeitet 21.11.2024 04:58:11

An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET request to a certain URL and obtain information that should be provided to authenticated users only.

Exploit
  • EPSS 0.88%
  • Veröffentlicht 06.04.2020 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:58:11

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to two files that contain customer data and application paths.