Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In March 2020
An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authenticated user to view sensitive information being logged via diagnose debug commands.
CVSS Score
6.5
EPSS Score
0.003
Published
2020-03-13
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of managed systems, being written to a log file in clear text. This only affects LXCA version 2.6.0 when performing a Windows driver update. Affected logs are only accessible to authorized users in the First Failure Data Capture (FFDC) service log and log files on LXCA.
CVSS Score
7.9
EPSS Score
0.001
Published
2020-03-13
Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.
CVSS Score
6.1
EPSS Score
0.008
Published
2020-03-13
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation.
CVSS Score
6.1
EPSS Score
0.003
Published
2020-03-13
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.
CVSS Score
10.0
EPSS Score
0.027
Published
2020-03-13
Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.
CVSS Score
8.8
EPSS Score
0.002
Published
2020-03-13
Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108.
CVSS Score
9.8
EPSS Score
0.023
Published
2020-03-13
Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the absence of a configured root chain of trust.
CVSS Score
9.1
EPSS Score
0.001
Published
2020-03-13
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contained in two ranges, one of which is locally disabled.
CVSS Score
9.8
EPSS Score
0.004
Published
2020-03-12
GitLab 12.8.x before 12.8.6, when sign-up is enabled, allows remote attackers to bypass email domain restrictions within the two-day grace period for an unconfirmed email address.
CVSS Score
5.3
EPSS Score
0.002
Published
2020-03-12


Contact Us

Shodan ® - All rights reserved