CVE-2024-4894
- EPSS 0.17%
- Veröffentlicht 15.05.2024 03:15:14
- Zuletzt bearbeitet 21.11.2024 09:43:48
ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modify the parameters and conduct Server-Side Request Forgery (SSRF) attacks. This vulnerability enables attackers to probe internal ne...
CVE-2023-48373
- EPSS 0.1%
- Veröffentlicht 15.12.2023 05:15:08
- Zuletzt bearbeitet 21.11.2024 08:31:35
ITPison OMICARD EDM has a path traversal vulnerability within its parameter “FileName” in a specific function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
CVE-2023-48372
- EPSS 0.67%
- Veröffentlicht 15.12.2023 05:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:35
ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.
CVE-2023-48371
- EPSS 0.61%
- Veröffentlicht 15.12.2023 04:15:06
- Zuletzt bearbeitet 21.11.2024 08:31:35
ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or...
CVE-2023-32753
- EPSS 0.4%
- Veröffentlicht 16.06.2023 04:15:13
- Zuletzt bearbeitet 21.11.2024 08:03:58
OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt...
CVE-2023-28700
- EPSS 0.04%
- Veröffentlicht 02.06.2023 11:15:10
- Zuletzt bearbeitet 21.11.2024 07:55:49
OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area network attacker with administrator privileges can exploit this vulnerability to upload and run arbitrary executable files to perf...