CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rocketsoftware 1Trufusion Enterprise Apr 3, 2026 Feb 17, 2026 7.9 HIGH· v4 7.3 HIGH· v3 N/A· v2 Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the pr...Show more |
1Rocketsoftware 1Trufusion Enterprise Apr 3, 2026 Feb 17, 2026 9.4 CRITICAL· v4 9.9 CRITICAL· v3 N/A· v2 Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDire...Show more |
1Rocketsoftware 1Trufusion Enterprise Oct 31, 2025 Oct 27, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to unauthent...Show more |
1Rocketsoftware 1Trufusion Enterprise Oct 31, 2025 Oct 27, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal seque...Show more |
1Rocketsoftware 1Trufusion Enterprise Oct 31, 2025 Oct 27, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the enc...Show more |
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traver...Show more |
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?"...Show more |
A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP request to /trufusionPortal/upDwModuleProx...Show more |