Vulnerabilities
Vulnerable Software
SQL Injection vulnerability in "Documents component" found in AudimexEE version 14.1.0 allows an attacker to execute arbitrary SQL commands via the object_path parameter.
CVSS Score
8.8
EPSS Score
0.003
Published
2020-11-05
AudimexEE before 14.1.1 is vulnerable to Reflected XSS (Cross-Site-Scripting). If the recommended security configuration parameter "unique_error_numbers" is not set, remote attackers can inject arbitrary web script or HTML via 'action, cargo, panel' parameters that can lead to data leakage.
CVSS Score
5.4
EPSS Score
0.002
Published
2020-11-05


Contact Us

Shodan ® - All rights reserved