CVE-2023-33291
- EPSS 0.08%
- Veröffentlicht 28.05.2023 22:15:09
- Zuletzt bearbeitet 14.01.2025 19:15:30
In ebankIT 6, the public endpoints /public/token/Email/generate and /public/token/SMS/generate allow generation of OTP messages to any e-mail address or phone number without validation. (It cannot be exploited with e-mail addresses or phone numbers t...
CVE-2023-30454
- EPSS 0.11%
- Veröffentlicht 28.04.2023 19:15:16
- Zuletzt bearbeitet 30.01.2025 21:15:12
An issue was discovered in ebankIT before 7. Document Object Model based XSS exists within the /Security/Transactions/Transactions.aspx endpoint. Users can supply their own JavaScript within the ctl100$ctl00MainContent$TransactionMainContent$accContr...
CVE-2023-30455
- EPSS 0.09%
- Veröffentlicht 28.04.2023 18:15:26
- Zuletzt bearbeitet 30.01.2025 21:15:12
An issue was discovered in ebankIT before 7. A Denial-of-Service attack is possible through the GET parameter EStatementsIds located on the /Controls/Generic/EBMK/Handlers/EStatements/DownloadEStatement.ashx endpoint. The GET parameter accepts over 1...