汇总 ebrigade 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。
常见弱点模式包括 SQL 注入与路径处理缺陷,在 软件部署与生产负载 使用场景中可能带来 数据泄露与文件覆盖 等风险。
相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。
| CVE | 摘要 | 来源 | 最高 CVSS | EPSS % | 公开时间 | 更新时间 |
|---|---|---|---|---|---|---|
| CVE-2019-25707 | eBrigade ERP 4.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to pdf.php with crafted SQL payloads in the 'id' parameter to extract sensitive database information including table names and schema details. | [email protected] | 7.1 | 0.27% | 2026-04-12 | 2026-06-16 |
| CVE-2019-16745 | eBrigade before 5.0 has evenement_choice.php chxCal SQL Injection. | [email protected] | 8.8 | 1.74% | 2019-09-30 | 2026-06-16 |
| CVE-2019-16744 | eBrigade before 5.0 has evenements.php cid SQL Injection. | [email protected] | 8.8 | 1.74% | 2019-09-30 | 2026-06-16 |
| CVE-2019-16743 | eBrigade before 5.0 has evenement_ical.php evenement SQL Injection. | [email protected] | 8.8 | 1.74% | 2019-09-30 | 2026-06-16 |
| CVE-2019-9622 | eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as demonstrated by reading the user-data/save/backup.sql file. | [email protected] | 4.3 | 4.88% | 2019-03-07 | 2026-06-16 |