← Back

Ruvaroa

ruvaroa

Vendor: Ruvar • 26 CVEs

CVEs (26)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.4 CRITICAL· v3
N/A· v2
Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx). This vulnerability can allow attackers to write files to the server or execute arbitr...Show more
Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx). This vulnerability can allow attackers to write files to the server or execute arbitrary commands via crafted SQL statements.Show less
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/get_dict.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_show.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/SearchCondiction.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/get_find_condiction.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_office_file_history_show.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.4 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_show.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the project_id parameter at /ProjectManage/pm_gatt_inc.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownload.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.4 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkPlan/WorkPlanAttachDownLoad.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.4 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at /WorkFlow/wf_work_form_save.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.4 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_company.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys_blogtemplate_new.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.4 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /WorkFlow/wf_get_fields_approve.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 8, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_work_finish_file_down.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 7, 2024
N/A· v4
9.4 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /SysManage/wf_template_child_field_list.aspx.
1Ruvar
1Ruvaroa
Jun 17, 2026
May 7, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /CorporateCulture/kaizen_download.aspx.