Leostream
Leostream Connection Broker: vulnerabilidades y CVE
Leostream Connection Broker tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-41551 | Media (4.9) | 1.3% | — | 18 ene 2022 | Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link. |
| CVE-2021-41550 | Alta (7.2) | 0.96% | — | 18 ene 2022 | Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code. |
| CVE-2021-38157 | Media (6.1) | 1.1% | — | 6 ago 2021 | LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer |
| CVE-2020-26574 | Crítica (9.6) | 2.1% | — | 6 oct 2020 | Leostream Connection Broker 8.2.x is affected by stored XSS. An unauthenticated attacker can inject arbitrary JavaScript code via the webquery.pl User-Agent HTTP header. It is rendered by the admins the next time they… |
| CVE-2018-18817 | Alta (7.5) | 1.1% | — | 30 oct 2018 | The Leostream Agent before Build 7.0.1.0 when used with Leostream Connection Broker 8.2.72 or earlier allows remote attackers to modify registry keys via the Leostream Agent API. |