Inedo
Inedo Proget: vulnerabilidades y CVE
Inedo Proget tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-1420 | Baja (2.4) | 0.23% | — | 21 may 2025 | Input provided in a field containing "activationMessage" in Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack. This issue has been fixed in 2.17.5… |
| CVE-2025-1419 | Baja (2.4) | 0.23% | — | 21 may 2025 | Input provided in comment section of Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack. This issue has been fixed in 2.17.5 version of Konsola… |
| CVE-2025-1418 | Media (5.1) | 0.18% | — | 21 may 2025 | A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which contain details about allowed/prohibited functions. The profiles do not reveal any sensitive… |
| CVE-2025-1417 | Media (4.6) | 0.18% | — | 21 may 2025 | In Proget MDM, a low-privileged user can access information about changes contained in backups of all devices managed by the MDM (Mobile Device Management). This information include user ids, email addresses, first… |
| CVE-2025-1416 | Alta (7) | 0.19% | — | 21 may 2025 | In Proget MDM, a low-privileged user can retrieve passwords for managed devices and subsequently use functionalities restricted by the MDM (Mobile Device Management). For it to happen, they must know the UUIDs of… |
| CVE-2025-1415 | Media (5.1) | 0.21% | — | 21 may 2025 | A low-privileged user is able to obtain information about tasks executed on devices controlled by Proget MDM (Mobile Device Management), as well as details of the devices like their UUIDs needed for exploitation of… |
| CVE-2025-47244 | Alta (7.3) | 0.47% | — | 3 may 2025 | Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, as demonstrated by causing a denial of service (when an attacker executes a loop calling… |
| CVE-2017-15608 | Media (6.5) | 0.41% | — | 26 sept 2018 | Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings. |
| CVE-2017-14944 | Alta (7.5) | 0.86% | — | 30 sept 2017 | Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060. |