← Back

Ciges

ciges

Vendor: Atisoluciones • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atisoluciones
1Ciges
Jun 17, 2026
Mar 22, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept traffic due to the lack of proper implementation of the TLS protocol.
1Atisoluciones
1Ciges
Jun 17, 2026
Mar 22, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify elements of the website and email confirmation message.
1Atisoluciones
1Ciges
Jun 17, 2026
Mar 22, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and store malicious javascript code in the application form without prior registration.
1Atisoluciones
1Ciges
Jun 17, 2026
Mar 22, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all installed packages used by the application.
1Atisoluciones
1Ciges
Jun 17, 2026
Mar 22, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL injection vulnerability in the CIGESv2 system, through /ajaxServiciosAtencion.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the da...Show more
SQL injection vulnerability in the CIGESv2 system, through /ajaxServiciosAtencion.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.Show less
1Atisoluciones
1Ciges
Jun 17, 2026
Mar 22, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL injection vulnerability in the CIGESv2 system, through /ajaxSubServicios.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the databas...Show more
SQL injection vulnerability in the CIGESv2 system, through /ajaxSubServicios.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.Show less
1Atisoluciones
1Ciges
Jun 17, 2026
Mar 22, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL injection vulnerability in the CIGESv2 system, through /ajaxConfigTotem.php, in the 'id' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by send...Show more
SQL injection vulnerability in the CIGESv2 system, through /ajaxConfigTotem.php, in the 'id' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.Show less