Ocomon Project
Ocomon Project Ocomon: vulnerabilidades y CVE
Ocomon Project Ocomon tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-33559 | Alta (8.8) | 0.68% | — | 26 oct 2023 | A local file inclusion vulnerability via the lang parameter in OcoMon before v4.0.1 allows attackers to execute arbitrary code by supplying a crafted PHP file. |
| CVE-2023-33558 | Alta (7.5) | 0.53% | — | 26 oct 2023 | An information disclosure vulnerability in the component users-grid-data.php of Ocomon before v4.0.1 allows attackers to obtain sensitive information such as e-mails and usernames. |
| CVE-2022-40798 | Alta (7.5) | 0.87% | — | 19 oct 2022 | OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct email its possible to account takeover. |
| CVE-2022-41391 | Crítica (9.8) | 0.81% | — | 13 oct 2022 | OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php. |
| CVE-2022-41390 | Crítica (9.8) | 0.81% | — | 13 oct 2022 | OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php. |