Processmaker

Processmaker

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 32.11%
  • Veröffentlicht 10.07.2025 19:12:37
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to improper handling of uploaded plugin archives. An attacker with administrative privileges can upload a malicious .tar plugin file containing arbitrary PHP...

  • EPSS 0.58%
  • Veröffentlicht 28.03.2024 20:15:07
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie.

Exploit
  • EPSS 14.04%
  • Veröffentlicht 19.09.2022 16:15:11
  • Zuletzt bearbeitet 03.06.2025 19:15:31

ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.

Exploit
  • EPSS 1.59%
  • Veröffentlicht 10.12.2020 23:15:11
  • Zuletzt bearbeitet 21.11.2024 05:01:25

SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and clientSetupAjax pages are vulnerable to SQL injection in the sort par...

Exploit
  • EPSS 1.59%
  • Veröffentlicht 03.12.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 05:01:25

The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticate...

Exploit
  • EPSS 0.58%
  • Veröffentlicht 17.09.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:00:30

A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter t...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 10.09.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:00:30

Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks ...