opendesa CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

opendesa vulnerability overview

Aggregates CVE and security vulnerability intelligence across all opendesa-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk cross-site scripting and vendor risk csrf; exposure may include vendor impact session compromise in vendor surface software deployment and vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2018-13040 OpenSID 18.06-pasca has a CSRF vulnerability. This vulnerability can add an account (at the admin level) via the index.php/man_user/insert URI. [email protected] 8.8 0.14% 2018-07-01 2024-11-21
CVE-2018-13039 OpenSID 18.06-pasca has reflected Cross Site Scripting (XSS) via the cari parameter, aka an index.php/first?cari= URI. [email protected] 6.1 0.24% 2018-07-01 2024-11-21
CVE-2018-13038 OpenSID 18.06-pasca has an Unrestricted File Upload vulnerability via an Attachment Document in the article feature. This vulnerability leads to uploading arbitrary PHP code via a .php filename with the application/pdf Content-Type. [email protected] 9.8 0.43% 2018-07-01 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence