Saltos
Saltos Rhinos: vulnerabilities and CVEs
Saltos Rhinos has 4 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months0
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5409 | Medium (6.1) | 0.28% | — | May 27, 2024 | RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a victim to obtain their session details. |
| CVE-2024-5408 | Medium (6.1) | 0.33% | — | May 27, 2024 | Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of a victim's user session by submitting a… |
| CVE-2024-5407 | Critical (9.8) | 0.60% | — | May 27, 2024 | A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform a reverse shell on the remote system,… |
| CVE-2018-18760 | Medium (6.5) | 2.6% | — | Nov 16, 2018 | RhinOS 3.0 build 1190 allows CSRF. |