← Back

Konzept Ix

konzept-ix

5 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Publixone
publixone

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Konzept Ix
1Publixone
Nov 21, 2024
Oct 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to disclose sensitive user information, send arbitrary e-mails, escalate the privileges of arbitrary user ac...Show more
A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to disclose sensitive user information, send arbitrary e-mails, escalate the privileges of arbitrary user accounts, and have unspecified other impact.Show less
1Konzept Ix
1Publixone
Nov 21, 2024
Oct 27, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to inject arbitrary JavaScript or HTML via appletError.jsp, job_jacket_detail.jsp, ixedit/editor_componen...Show more
Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to inject arbitrary JavaScript or HTML via appletError.jsp, job_jacket_detail.jsp, ixedit/editor_component.jsp, or the login form.Show less
1Konzept Ix
1Publixone
Nov 21, 2024
Oct 27, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or decrypt server-side configuration files.
1Konzept Ix
1Publixone
Nov 21, 2024
Oct 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.
1Konzept Ix
1Publixone
Nov 21, 2024
Oct 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens.