Junhetec
junhetec
4 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Junhetec 1Omnidirectional Communication System Jun 17, 2026 May 7, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Local File Inclusion vulnerability of the omni-directional communication system allows remote authenticated attacker inject absolute path into Url parameter and access arbitrary file. |
1Junhetec 1Omnidirectional Communication System Jun 17, 2026 May 7, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Special characters of picture preview page in the Quan-Fang-Wei-Tong-Xun system are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out Reflected XSS (Cr...Show more |
1Junhetec 1Enterprise Resource Planning Point Of Sale System Jun 17, 2026 May 7, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Special characters of ERP POS news page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additio...Show more |
1Junhetec 1Enterprise Resource Planning Point Of Sale System Jun 17, 2026 May 7, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) atta...Show more |