kardex CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

kardex vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to kardex, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-22855 Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is handed to a path-concatenation method (Path.Combine from .NET) without proper sanitisation. This yields the possibility of including local files, as well as remote files on SMB shares. If one provides a file with the extension .t4, it is rendered with the .NET templating engine mono/t4, which can execute code. [email protected] 9.8 61.57% 2023-02-15 2025-03-19
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence