Aggregates CVE and security vulnerability intelligence across all misstt123-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Disclosed issues often relate to vendor risk csrf and vendor risk path handling; exposure may include vendor impact file overwrite in vendor surface production workloads and vendor surface software deployment contexts.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-3687 | A vulnerability, which was classified as problematic, has been found in misstt123 oasys 1.0. Affected by this issue is some unknown functionality of the component Sticky Notes Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. | [email protected] | 5.3 | 0.23% | 2025-04-16 | 2025-06-25 |
| CVE-2025-3686 | A vulnerability classified as problematic was found in misstt123 oasys 1.0. Affected by this vulnerability is the function image of the file /show. The manipulation leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. | [email protected] | 5.3 | 0.67% | 2025-04-16 | 2025-06-25 |
| CVE-2024-48270 | An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack. | [email protected] | 7.5 | 0.18% | 2024-11-01 | 2025-07-07 |