← Back

Openbmcs

openbmcs

5 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Openbmcs
openbmcs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openbmcs
1Openbmcs
Jun 17, 2026
Dec 9, 2025
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive files by exploiting directory listing functionality. Attackers can browse directories like /debug/ a...Show more
OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive files by exploiting directory listing functionality. Attackers can browse directories like /debug/ and /php/ to discover configuration files, database credentials, and system information.Show less
1Openbmcs
1Openbmcs
Jun 17, 2026
Dec 9, 2025
8.7 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malici...Show more
OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information.Show less
1Openbmcs
1Openbmcs
Jun 17, 2026
Dec 9, 2025
6.9 MEDIUM· v4
7.2 HIGH· v3
N/A· v2
OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass firewalls and initiate service and network enumeration on the internal network through the affected application, allowing hijack...Show more
OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass firewalls and initiate service and network enumeration on the internal network through the affected application, allowing hijacking of current sessions. Attackers can specify an external domain in the 'ip' parameter to force the application to make an HTTP request to an arbitrary destination host.Show less
1Openbmcs
1Openbmcs
Jun 17, 2026
Dec 9, 2025
5.3 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
OpenBMCS 2.4 contains a CSRF vulnerability that allows attackers to perform actions with administrative privileges by exploiting the sendFeedback.php endpoint. Attackers can submit malicious requests to trigger unintende...Show more
OpenBMCS 2.4 contains a CSRF vulnerability that allows attackers to perform actions with administrative privileges by exploiting the sendFeedback.php endpoint. Attackers can submit malicious requests to trigger unintended actions, such as sending emails or modifying system settings.Show less
1Openbmcs
1Openbmcs
Jun 17, 2026
Dec 9, 2025
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permissions and exploiting a vulnerability in the update_user_permissions.php script. Attackers can submit a malic...Show more
OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permissions and exploiting a vulnerability in the update_user_permissions.php script. Attackers can submit a malicious HTTP POST request to PHP scripts in '/plugins/useradmin/' directory.Show less