« Volver al listado

Volosoft

Volosoft ABP: vulnerabilidades y CVE

Volosoft ABP tiene 3 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE3
Últimos 12 meses2
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-65581Media (5.3)0.28%—16 dic 2025
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect…
CVE-2025-13051Crítica (9.3)0.19%—19 nov 2025
When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replace or plant a DLL with the same name as one loaded by the service. Upon service restart, the…
CVE-2025-8070Crítica (9.2)0.16%—23 jul 2025
The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a malicious executable in a predictable…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation2
  2. T1059 Command and Scripting Interpreter1
  3. T1574.007 Path Interception by PATH Environment Variable1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.