« Back to list

Infodom

Infodom Performa 365: vulnerabilities and CVEs

Infodom Performa 365 has 2 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-46624High (8.8)0.43%—Dec 3, 2024
An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via a crafted payload sent to /api/users.
CVE-2024-46625High (8.8)0.55%—Dec 3, 2024
An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services2
  2. T1068 Exploitation for Privilege Escalation1
  3. T1505.003 Web Shell1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.