Vulnerabilities
Vulnerable Software
Ragic:  Security Vulnerabilities
Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
CVSS Score
7.5
EPSS Score
0.003
Published
2024-10-15
Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.
CVSS Score
9.8
EPSS Score
0.004
Published
2024-10-15
Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server.
CVSS Score
10.0
EPSS Score
0.003
Published
2024-10-15
Rogic No-Code Database Builder's file uploading function has insufficient filtering for special characters. A remote attacker with regular user privilege can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack.
CVSS Score
5.4
EPSS Score
0.001
Published
2023-11-03
Ragic report generation page has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript to perform XSS (Reflected Cross-Site Scripting) attack.
CVSS Score
5.4
EPSS Score
0.001
Published
2022-10-31


Contact Us

Shodan ® - All rights reserved