CVE-2024-31842
- EPSS 0.28%
- Veröffentlicht 20.08.2024 20:15:08
- Zuletzt bearbeitet 29.10.2024 21:35:06
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be saved in the browser's history, passed through Referers to other web si...
CVE-2024-31843
- EPSS 0.14%
- Veröffentlicht 23.05.2024 19:16:01
- Zuletzt bearbeitet 21.05.2025 18:18:40
An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are processed on the server side. This allows authenticated users to execute commands on the Operating System.
CVE-2024-31844
- EPSS 0.14%
- Veröffentlicht 21.05.2024 16:15:26
- Zuletzt bearbeitet 13.03.2025 21:15:38
An issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases, this leads to a disclosure of information about the server. An unauthenticated user is able craft specific requests in order to m...
CVE-2024-31845
- EPSS 0.18%
- Veröffentlicht 21.05.2024 16:15:26
- Zuletzt bearbeitet 21.05.2025 18:18:51
An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an atta...
CVE-2024-31847
- EPSS 0.47%
- Veröffentlicht 21.05.2024 16:15:26
- Zuletzt bearbeitet 13.03.2025 18:15:40
An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated and unauthenticated remote attackers to inject arbitrary web script or HTML into a GET parameter. This reflects/stores the user i...
CVE-2024-31840
- EPSS 0.15%
- Veröffentlicht 21.05.2024 16:15:25
- Zuletzt bearbeitet 14.03.2025 15:15:40
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration of the email server. Once the user access the edit function, the web ap...
CVE-2024-31841
- EPSS 0.3%
- Veröffentlicht 19.04.2024 16:15:10
- Zuletzt bearbeitet 21.05.2025 18:20:10
An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.
CVE-2024-31846
- EPSS 0.17%
- Veröffentlicht 19.04.2024 16:15:10
- Zuletzt bearbeitet 21.05.2025 18:19:47
An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.