← Back

Qsige

qsige

Vendor: Qsige • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qsige
1Qsige
Nov 21, 2024
Oct 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prere...Show more
QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.Show less
1Qsige
1Qsige
Nov 21, 2024
Oct 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.
1Qsige
1Qsige
Nov 21, 2024
Oct 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.
1Qsige
1Qsige
Nov 21, 2024
Oct 3, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
Allows an attacker to perform XSS attacks stored on certain resources. Exploiting this vulnerability can lead to a DoS condition, among other actions.
1Qsige
1Qsige
Nov 21, 2024
Oct 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application...Show more
The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.Show less
1Qsige
1Qsige
Nov 21, 2024
Oct 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.
1Qsige
1Qsige
Nov 21, 2024
Oct 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attacker to log into the application with a valid username.