Zucchetti
Zucchetti Infobusiness: vulnerabilities and CVEs
Zucchetti Infobusiness has 4 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18207 | Medium (5.4) | 0.52% | — | Oct 30, 2019 | In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field in the InfoBusiness Web Component. The payload will be triggered… |
| CVE-2019-18206 | High (8.8) | 0.46% | — | Oct 30, 2019 | A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload. |
| CVE-2019-18205 | Medium (6.1) | 0.67% | — | Oct 30, 2019 | Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base64). This also… |
| CVE-2019-18204 | High (8.8) | 1.7% | — | Oct 30, 2019 | Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve code execution. |