CVE-2023-37373
- EPSS 0.29%
- Published 08.08.2023 10:15:15
- Last modified 21.11.2024 08:11:36
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications accept unauthenticated file write messages. An unauthenticated remote attacker could write arbitrary files to the affected application's file s...
CVE-2023-27411
- EPSS 0.57%
- Published 08.08.2023 10:15:14
- Last modified 21.11.2024 07:52:51
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an authenticated remote attackers to execute arbitrary SQL queries on the server database and ...
CVE-2023-27462
- EPSS 0.13%
- Published 14.03.2023 10:15:29
- Last modified 21.11.2024 07:52:57
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The client query handler of the affected application fails to check for proper permissions for specific read queries. This could allow authenticated remote attackers to ...
CVE-2023-27463
- EPSS 0.57%
- Published 14.03.2023 10:15:29
- Last modified 21.11.2024 07:52:57
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The audit log form of affected applications is vulnerable to SQL injection. This could allow authenticated remote attackers to execute arbitrary SQL queries on the serve...
CVE-2023-27309
- EPSS 0.22%
- Published 14.03.2023 10:15:28
- Last modified 21.11.2024 07:52:37
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions for specific write queries. This could allow an authenticated remote attacker ...
CVE-2023-27310
- EPSS 0.25%
- Published 14.03.2023 10:15:28
- Last modified 21.11.2024 07:52:37
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions when assigning groups to user accounts. This could allow an authenticated remo...