ocomon_project CVE Vulnerabilities & CVE List (5)

Products (CPE): — CVEs: 5

ocomon_project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all ocomon_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk sql injection and vendor risk cross-site scripting and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 15 of 5 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-33559 A local file inclusion vulnerability via the lang parameter in OcoMon before v4.0.1 allows attackers to execute arbitrary code by supplying a crafted PHP file. [email protected] 8.8 0.68% 2023-10-26 2024-11-21
CVE-2023-33558 An information disclosure vulnerability in the component users-grid-data.php of Ocomon before v4.0.1 allows attackers to obtain sensitive information such as e-mails and usernames. [email protected] 7.5 0.53% 2023-10-26 2024-11-21
CVE-2022-40798 OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct email its possible to account takeover. [email protected] 7.5 0.78% 2022-10-19 2025-05-08
CVE-2022-41391 OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php. [email protected] 9.8 0.75% 2022-10-13 2025-05-15
CVE-2022-41390 OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php. [email protected] 9.8 0.75% 2022-10-13 2025-05-15
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence