Saltos
Saltos Rhinos: vulnerabilidades y CVE
Saltos Rhinos tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-5409 | Media (6.1) | 0.28% | — | 27 may 2024 | RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a victim to obtain their session details. |
| CVE-2024-5408 | Media (6.1) | 0.33% | — | 27 may 2024 | Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of a victim's user session by submitting a… |
| CVE-2024-5407 | Crítica (9.8) | 0.60% | — | 27 may 2024 | A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform a reverse shell on the remote system,… |
| CVE-2018-18760 | Media (6.5) | 2.6% | — | 16 nov 2018 | RhinOS 3.0 build 1190 allows CSRF. |