Scriptcase

Scriptcase

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.34%
  • Veröffentlicht 05.07.2025 00:00:00
  • Zuletzt bearbeitet 08.07.2025 16:18:53

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypas...

  • EPSS 5.73%
  • Veröffentlicht 05.07.2025 00:00:00
  • Zuletzt bearbeitet 08.07.2025 16:18:53

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allows authenticated attackers to execute system commands via crafted HTTP requests.

  • EPSS 0.78%
  • Veröffentlicht 26.03.2025 00:00:00
  • Zuletzt bearbeitet 27.03.2025 16:45:27

HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate privileges via a crafted request.

  • EPSS 0.21%
  • Veröffentlicht 26.03.2025 00:00:00
  • Zuletzt bearbeitet 08.04.2025 19:15:48

A cross-site scripting (XSS) vulnerability in ScriptCase before v1.0.003 - Build 3 allows attackers to execute arbitrary code via a crafted payload to the "Connection Name" in the New Connection and Rename Connection pages.

Exploit
  • EPSS 1.79%
  • Veröffentlicht 01.10.2024 21:15:06
  • Zuletzt bearbeitet 28.04.2025 17:17:16

Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 01.10.2024 21:15:06
  • Zuletzt bearbeitet 28.04.2025 17:17:29

Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.

Exploit
  • EPSS 1.79%
  • Veröffentlicht 01.10.2024 21:15:06
  • Zuletzt bearbeitet 28.04.2025 17:17:46

Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 01.10.2024 19:15:09
  • Zuletzt bearbeitet 28.04.2025 17:16:59

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is im...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 01.10.2024 19:15:08
  • Zuletzt bearbeitet 28.04.2025 17:16:42

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 01.10.2024 19:15:08
  • Zuletzt bearbeitet 28.04.2025 17:16:25

Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned...