Cipplanner
Cipplanner Cipace: vulnerabilidades y CVE
Cipplanner Cipace tiene 18 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses4
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-50619 | Alta (8.8) | 0.25% | — | 11 feb 2026 | Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated user can gain access to other people's… |
| CVE-2024-50617 | Alta (7.5) | 0.25% | — | 11 feb 2026 | Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file id parameter or pass… |
| CVE-2024-50620 | Alta (8.8) | 0.31% | — | 11 feb 2026 | Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage components in CIPPlanner CIPAce before 9.17. An authorized user can upload executable files when… |
| CVE-2024-50618 | Media (4.3) | 0.26% | — | 11 feb 2026 | A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypass a protection mechanism. When the system is configured to allow login with… |
| CVE-2020-11587 | Alta (7.5) | 1.2% | — | 6 abr 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and get the content of ETL Processes running on the server. |
| CVE-2020-11586 | Crítica (9.8) | 1.2% | — | 6 abr 2020 | An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XML DTD data. |
| CVE-2020-11599 | Alta (7.5) | 1.1% | — | 6 abr 2020 | An issue was discovered in CIPPlanner CIPAce 6.80 Build 2016031401. GetDistributedPOP3 allows attackers to obtain the username and password of the SMTP user. |
| CVE-2020-11598 | Crítica (9.8) | 2.5% | — | 6 abr 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and executing an ASHX file. |
| CVE-2020-11597 | Crítica (9.8) | 1.5% | — | 6 abr 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request and inject SQL statements in the user context of the db owner. |
| CVE-2020-11596 | Alta (7.5) | 1.8% | — | 6 abr 2020 | A Directory Traversal issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make HTTP GET requests to a certain URL and obtain information about what files and directories… |
| CVE-2020-11595 | Alta (7.5) | 1.2% | — | 6 abr 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and obtain the upload folder path that includes the hostname in a UNC path. |
| CVE-2020-11594 | Alta (7.5) | 1.2% | — | 6 abr 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that causes a stack error to be shown providing the full file path. |
| CVE-2020-11593 | Alta (7.5) | 0.99% | — | 6 abr 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to send emails from a customer trusted email… |
| CVE-2020-11592 | Alta (7.5) | 1.2% | — | 6 abr 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and get the columns of a specific table within the CIP database. |
| CVE-2020-11591 | Media (5.3) | 0.96% | — | 6 abr 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and obtain the full application path along with the customer name. |
| CVE-2020-11590 | Media (5.3) | 0.96% | — | 6 abr 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to HealthPage.aspx and obtain the internal server name. |
| CVE-2020-11589 | Alta (7.5) | 1.1% | — | 6 abr 2020 | An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET request to a certain URL and obtain information that should be provided to… |
| CVE-2020-11588 | Media (5.3) | 0.96% | — | 6 abr 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to two files that contain customer data and application paths. |