CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Junhetec 1Omnidirectional Communication System Jun 17, 2026 May 7, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Local File Inclusion vulnerability of the omni-directional communication system allows remote authenticated attacker inject absolute path into Url parameter and access arbitrary file. |
1Junhetec 1Omnidirectional Communication System Jun 17, 2026 May 7, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Special characters of picture preview page in the Quan-Fang-Wei-Tong-Xun system are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out Reflected XSS (Cr...Show more |