CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks. |
eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file. |