CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Changingtec 1Rava Certificate Validation System Nov 21, 2024 Oct 18, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access arbitrary system files. |
1Changingtec 1Rava Certificate Validation System Nov 21, 2024 Oct 18, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 RAVA certificate validation system has insufficient filtering for special parameter of the web page input field. A remote attacker with administrator privilege can exploit this vulnerability to perform arbitrary system c...Show more |
1Changingtec 1Rava Certificate Validation System Nov 21, 2024 Oct 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify and delete database. |
1Changingtec 1Rava Certificate Validation System Nov 21, 2024 Oct 18, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover internal network topology base on query response. |