Midasolutions
Midasolutions Eframework: vulnerabilidades y CVE
Midasolutions Eframework tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-15924 | Alta (7.5) | 1.9% | — | 24 jul 2020 | There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in one of the authentication parameters. |
| CVE-2020-15923 | Alta (7.5) | 3.3% | — | 24 jul 2020 | Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal. |
| CVE-2020-15922 | Crítica (9.8) | 57% | — | 24 jul 2020 | There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required. |
| CVE-2020-15921 | Crítica (9.8) | 18% | — | 24 jul 2020 | Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution. |
| CVE-2020-15920 | Crítica (9.8) | 98% | — | 24 jul 2020 | There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required. |
| CVE-2020-15919 | Media (6.1) | 0.94% | — | 24 jul 2020 | A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0. |
| CVE-2020-15918 | Media (5.4) | 0.56% | — | 24 jul 2020 | Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0. |