Italtel
Italtel Embrace: vulnerabilidades y CVE
Italtel Embrace tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-31842 | Alta (8.8) | 0.41% | — | 20 ago 2024 | An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be saved in the browser's history, passed… |
| CVE-2024-31843 | Media (4.1) | 0.54% | — | 23 may 2024 | An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are processed on the server side. This allows authenticated users to execute… |
| CVE-2024-31847 | Media (6.1) | 0.44% | — | 21 may 2024 | An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated and unauthenticated remote attackers to inject arbitrary web script or HTML into a GET parameter.… |
| CVE-2024-31845 | Media (5.3) | 0.44% | — | 21 may 2024 | An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This… |
| CVE-2024-31844 | Media (5.3) | 0.52% | — | 21 may 2024 | An issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases, this leads to a disclosure of information about the server. An unauthenticated user is able craft… |
| CVE-2024-31840 | Media (6.5) | 0.36% | — | 21 may 2024 | An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration of the email server. Once the user… |
| CVE-2024-31846 | Alta (7.5) | 0.66% | — | 19 abr 2024 | An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
| CVE-2024-31841 | Alta (7.5) | 0.80% | — | 19 abr 2024 | An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem. |