Vulnerabilities
Vulnerable Software
Cybelesoft:  Security Vulnerabilities
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.
CVSS Score
7.3
EPSS Score
0.003
Published
2024-11-13
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.
CVSS Score
4.8
EPSS Score
0.001
Published
2024-11-13
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.
CVSS Score
9.8
EPSS Score
0.004
Published
2024-11-13
Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.
CVSS Score
8.1
EPSS Score
0.004
Published
2024-11-13
A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.
CVSS Score
7.5
EPSS Score
0.004
Published
2024-11-13
Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can trick a user into browse malicious site, to obtain an 'ID' that can be used to send websocket requests and achieve RCE.
CVSS Score
8.8
EPSS Score
0.006
Published
2022-05-20
Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable server to filtrate the real IP of the web server or increase the attack surface.
CVSS Score
7.5
EPSS Score
0.128
Published
2022-02-09
Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI. By accessing the vector, an attacker can determine if a username exists thanks to the message returned; it can be presented in different languages according to the configuration of VirtualUI. Common users are administrator, admin, guest and krgtbt.
CVSS Score
5.3
EPSS Score
0.01
Published
2021-12-20
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.
CVSS Score
9.8
EPSS Score
0.4
Published
2021-12-16
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.
CVSS Score
5.3
EPSS Score
0.231
Published
2021-12-13


Contact Us

Shodan ® - All rights reserved