opencode ussd_gateway CVE 漏洞(6)

CVE 数: 6 CPE versions: View versions table

摘要

本页列出影响 opencode ussd_gateway 的已公开 CVE 漏洞(通过 NVD CPE 关联)。每行包含严重程度评分、摘要与发布日期,便于识别与分析安全问题。

显示 166 CVE 数
«« 第一页 « 上一页 第 1 / 1 页 下一页 »
CVE 摘要 来源 最高 CVSS EPSS % 公开时间 更新时间
CVE-2025-70614 OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing authenticated low-privileged attackers to gain to access to arbitrary SMS messages via a crafted company or tenant identifier parameter. [email protected] 8.1 0.26% 2026-03-05 2026-05-06
CVE-2025-65239 Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers with low-level privileges to read server logs. [email protected] 4.3 0.25% 2025-11-26 2025-12-30
CVE-2025-65238 Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with low-level privileges to dump user records and access sensitive information. [email protected] 6.5 0.29% 2025-11-26 2026-01-02
CVE-2025-65237 A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a user's browser via injecting a crafted payload. [email protected] 6.1 0.23% 2025-11-26 2026-01-02
CVE-2025-65236 OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpanel/index.php endpoint. [email protected] 9.8 0.39% 2025-11-26 2026-01-02
CVE-2025-65235 OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via the ID parameter in the getSubUsersByProvider function. [email protected] 9.8 0.38% 2025-11-26 2026-01-02
«« 第一页 « 上一页 第 1 / 1 页 下一页 »
cvelogic Threat Intelligence