Gladinet

Centrestack

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 30.07.2026 12:26:49
  • Zuletzt bearbeitet 30.07.2026 16:45:00

CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsond...

  • EPSS 0.19%
  • Veröffentlicht 30.07.2026 12:26:11
  • Zuletzt bearbeitet 30.07.2026 16:45:00

CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can gener...

  • EPSS 0.29%
  • Veröffentlicht 30.07.2026 12:25:36
  • Zuletzt bearbeitet 30.07.2026 16:45:00

CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage configuration handler. Attackers can send...

  • EPSS 0.22%
  • Veröffentlicht 30.07.2026 12:25:05
  • Zuletzt bearbeitet 31.07.2026 23:17:24

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endp...

  • EPSS 0.25%
  • Veröffentlicht 30.07.2026 12:24:44
  • Zuletzt bearbeitet 30.07.2026 16:45:00

CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into a crafted AccountName parameter posted to the SelectP...

  • EPSS 0.39%
  • Veröffentlicht 30.07.2026 12:24:15
  • Zuletzt bearbeitet 30.07.2026 16:45:00

CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket....

Warnung Medienbericht Exploit
  • EPSS 53.3%
  • Veröffentlicht 12.12.2025 21:01:13
  • Zuletzt bearbeitet 16.12.2025 13:48:02

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file...

Warnung Medienbericht Exploit
  • EPSS 92.09%
  • Veröffentlicht 09.10.2025 16:50:49
  • Zuletzt bearbeitet 05.11.2025 14:32:00

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wi...

Warnung
  • EPSS 93.84%
  • Veröffentlicht 03.04.2025 00:00:00
  • Zuletzt bearbeitet 05.11.2025 19:27:44

Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the m...

  • EPSS 0.98%
  • Veröffentlicht 22.11.2024 18:15:17
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.