CVE-2026-47755
- EPSS 0.27%
- Veröffentlicht 23.07.2026 17:08:24
- Zuletzt bearbeitet 28.07.2026 16:18:15
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by di...
CVE-2025-67081
- EPSS 0.25%
- Veröffentlicht 15.01.2026 15:15:50
- Zuletzt bearbeitet 23.01.2026 18:35:09
An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a profile. An attacker with admin account can exploit this issue via blind SQL injection, allowing for the extraction of arbitrary data...
CVE-2024-25344
- EPSS 0.74%
- Veröffentlicht 26.02.2024 16:27:58
- Zuletzt bearbeitet 25.04.2025 19:04:02
Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to execute arbitrary code and obtain sensitive information via the settings.php, settings+company.php, settings_default...