CVE-2024-10616
- EPSS 0.08%
- Veröffentlicht 01.11.2024 04:15:08
- Zuletzt bearbeitet 04.11.2024 16:44:56
A vulnerability classified as critical has been found in Tongda OA up to 11.9. This affects an unknown part of the file /pda/workflow/webSignSubmit.php. The manipulation of the argument saleId leads to sql injection. It is possible to initiate the at...
CVE-2024-10615
- EPSS 0.07%
- Veröffentlicht 01.11.2024 03:15:03
- Zuletzt bearbeitet 04.11.2024 16:45:15
A vulnerability was found in Tongda OA 2017 up to 11.10. It has been rated as critical. Affected by this issue is some unknown functionality of the file /general/approve_center/query/list/input_form/delete_data_attach.php. The manipulation of the arg...
CVE-2024-10602
- EPSS 0.07%
- Veröffentlicht 01.11.2024 00:15:02
- Zuletzt bearbeitet 04.11.2024 19:46:22
A vulnerability was found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this issue is some unknown functionality of the file /general/approve_center/list/input_form/data_picker_link.php. The manipulation of the argument dataSrc...
CVE-2024-10601
- EPSS 0.07%
- Veröffentlicht 31.10.2024 23:15:12
- Zuletzt bearbeitet 04.11.2024 19:45:45
A vulnerability has been found in Tongda OA 2017 up to 11.10 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /general/address/private/address/query/delete.php. The manipulation of the argument where_...
CVE-2024-10600
- EPSS 57.57%
- Veröffentlicht 31.10.2024 23:15:12
- Zuletzt bearbeitet 04.11.2024 19:45:26
A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.6. Affected is an unknown function of the file pda/appcenter/submenu.php. The manipulation of the argument appid leads to sql injection. It is possible to launch ...
CVE-2024-10599
- EPSS 0.1%
- Veröffentlicht 31.10.2024 22:15:03
- Zuletzt bearbeitet 04.11.2024 19:44:59
A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects some unknown processing of the file /inc/package_static_resources.php. The manipulation leads to resource consumption. The attack ma...
CVE-2024-10598
- EPSS 0.12%
- Veröffentlicht 31.10.2024 22:15:02
- Zuletzt bearbeitet 04.11.2024 19:44:05
A vulnerability classified as critical was found in Tongda OA 11.2/11.3/11.4/11.5/11.6. This vulnerability affects unknown code of the file general/hr/setting/attendance/leave/data.php of the component Annual Leave Handler. The manipulation leads to ...
CVE-2024-25320
- EPSS 0.13%
- Veröffentlicht 16.02.2024 15:15:08
- Zuletzt bearbeitet 19.03.2025 15:11:48
Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /affair/delete.php.
CVE-2024-1251
- EPSS 0.05%
- Veröffentlicht 06.02.2024 16:15:51
- Zuletzt bearbeitet 01.08.2025 02:09:10
A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /general/email/outbox/delete.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has bee...
CVE-2024-0938
- EPSS 0.06%
- Veröffentlicht 26.01.2024 18:15:10
- Zuletzt bearbeitet 19.03.2025 15:40:12
A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.9. This affects an unknown part of the file /general/email/inbox/delete_webmail.php. The manipulation of the argument WEBBODY_ID_STR leads to sql injection. The e...