CVE-2025-2488
- EPSS 0.17%
- Veröffentlicht 02.05.2025 11:30:10
- Zuletzt bearbeitet 12.09.2025 08:15:45
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Profelis Informatics SambaBox allows Cross-Site Scripting (XSS).This issue affects SambaBox: before 5.1.
CVE-2025-2421
- EPSS 0.38%
- Veröffentlicht 02.05.2025 11:27:49
- Zuletzt bearbeitet 12.09.2025 08:15:45
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Injection.This issue affects SambaBox: before 5.1.
CVE-2022-25619
- EPSS 0.2%
- Veröffentlicht 30.03.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:52:27
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause run arbitrary code. This issue affects: Profelis IT Consultancy Samb...
- EPSS 0.89%
- Veröffentlicht 30.03.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:52:27
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause execute arbitrary codes on the vulnerable server. This issue aff...