Ironmansoftware

Powershell Universal

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 17.03.2026 19:15:37
  • Zuletzt bearbeitet 19.03.2026 13:04:11

Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting...

  • EPSS 0.05%
  • Veröffentlicht 17.03.2026 19:14:17
  • Zuletzt bearbeitet 19.03.2026 13:03:28

Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensi...

  • EPSS 0.01%
  • Veröffentlicht 27.02.2026 15:11:18
  • Zuletzt bearbeitet 30.03.2026 21:17:10

The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file to obtain ...

  • EPSS 0.04%
  • Veröffentlicht 07.01.2026 17:00:21
  • Zuletzt bearbeitet 30.01.2026 01:41:53

Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13.

  • EPSS 0.17%
  • Veröffentlicht 27.10.2024 22:15:03
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Ironman PowerShell Universal 5.x before 5.0.12 allows an authenticated attacker to elevate their privileges and view job information.

Exploit
  • EPSS 1.55%
  • Veröffentlicht 23.11.2023 22:15:07
  • Zuletzt bearbeitet 21.11.2024 08:33:02

The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2...

  • EPSS 0.48%
  • Veröffentlicht 14.11.2022 08:15:09
  • Zuletzt bearbeitet 21.11.2024 07:28:55

Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve other app tokens by ID via an HTTP web request. Patched Versions are 3.5.3, 3.4.7, and 2.12.6.

  • EPSS 0.24%
  • Veröffentlicht 14.11.2022 08:15:09
  • Zuletzt bearbeitet 21.11.2024 07:28:55

The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory, which allows a remote attacker with administrator privilege to create, delete, update, and display files outs...