aceware CVE Vulnerabilities & CVE List (5)

Products (CPE): — CVEs: 5

aceware vulnerability overview

Aggregates CVE and security vulnerability intelligence across all aceware-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk sql injection and vendor risk cross-site scripting; exposure may include vendor impact session compromise and vendor impact data exposure in vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 15 of 5 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-24581 ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software. [email protected] 7.5 0.39% 2022-06-02 2024-11-21
CVE-2022-24241 ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the txtFilePath parameter in attachments.awp. [email protected] 7.5 0.39% 2022-06-02 2024-11-21
CVE-2022-24240 ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp. [email protected] 9.8 0.53% 2022-06-02 2024-11-21
CVE-2022-24239 ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp. [email protected] 9.8 0.73% 2022-06-02 2024-11-21
CVE-2022-24238 ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 parameter in person.awp. [email protected] 6.1 0.40% 2022-06-02 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence