Lcnet
Lcnet Smart Evision: vulnerabilidades y CVE
Lcnet Smart Evision tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-39035 | Media (6.1) | 0.61% | — | 28 sept 2022 | Smart eVision has insufficient filtering for special characters in the POST Data parameter in the specific function. An unauthenticated remote attacker can inject JavaScript to perform XSS (Stored Cross-Site Scripting)… |
| CVE-2022-39034 | Media (6.5) | 1.4% | — | 28 sept 2022 | Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special characters in URLs. A remote attacker with general user privilege can exploit this vulnerability to… |
| CVE-2022-39033 | Crítica (9.8) | 1.8% | — | 28 sept 2022 | Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability… |
| CVE-2022-39032 | Alta (8.8) | 0.89% | — | 28 sept 2022 | Smart eVision has an improper privilege management vulnerability. A remote attacker with general user privilege can exploit this vulnerability to escalate to administrator privilege, and then perform arbitrary system… |
| CVE-2022-39031 | Media (5.3) | 0.71% | — | 28 sept 2022 | Smart eVision has insufficient authorization for task acquisition function. An unauthorized remote attacker can exploit this vulnerability to acquire the Session IDs of other general users only. |
| CVE-2022-39030 | Alta (7.5) | 0.91% | — | 28 sept 2022 | smart eVision has inadequate authorization for system information query function. An unauthenticated remote attacker, who is not explicitly authorized to access the information, can access sensitive information. |
| CVE-2022-39029 | Media (6.5) | 0.78% | — | 28 sept 2022 | Smart eVision has inadequate authorization for the database query function. A remote attacker with general user privilege, who is not explicitly authorized to access the information, can access sensitive information. |