汇总 scriptcase 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。
已披露问题常与 跨站脚本与路径处理缺陷 相关,可能在 软件部署与生产负载 场景中带来 会话劫持与文件覆盖 等暴露风险。
相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。
| CVE | 摘要 | 来源 | 最高 CVSS | EPSS % | 公开时间 | 更新时间 |
|---|---|---|---|---|---|---|
| CVE-2025-47228 | In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allows authenticated attackers to execute system commands via crafted HTTP requests. | [email protected] | 6.7 | 14.44% | 2025-07-04 | 2026-06-17 |
| CVE-2025-47227 | In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover. | [email protected] | 7.5 | 1.96% | 2025-07-04 | 2026-06-17 |
| CVE-2024-46084 | Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function. | [email protected] | 8.0 | 0.75% | 2024-10-01 | 2026-07-04 |
| CVE-2024-46082 | Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters. | [email protected] | 5.4 | 0.29% | 2024-10-01 | 2026-06-17 |
| CVE-2024-46080 | Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function. | [email protected] | 8.0 | 0.75% | 2024-10-01 | 2026-06-17 |
| CVE-2024-46083 | Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is important to note that regular users can trigger actions for administrator users. | [email protected] | 5.4 | 0.27% | 2024-10-01 | 2026-06-17 |
| CVE-2024-46081 | Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to various users on the platform. | [email protected] | 5.4 | 0.30% | 2024-10-01 | 2026-06-17 |
| CVE-2024-46079 | Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter. | [email protected] | 6.1 | 0.32% | 2024-10-01 | 2026-06-17 |
| CVE-2024-8942 | Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials. | [email protected] | 6.3 | 0.32% | 2024-09-24 | 2026-06-17 |
| CVE-2024-8941 | Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via a “/...” or directly into a path used in the POST parameter “field_file” by a web application. | [email protected] | 7.5 | 0.60% | 2024-09-24 | 2026-06-17 |
| CVE-2024-8940 | Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input. | [email protected] | 10.0 | 0.53% | 2024-09-24 | 2026-06-17 |
| CVE-2022-32199 | db_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traversal sequence in the file parameter. | [email protected] | 6.5 | 1.66% | 2023-03-27 | 2026-06-17 |