Priority Software
priority-software
9 CVEs • 3 products
Products (3)
Click to collapseToggle
Products (3)
Click to collapse
CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Priority – CWE-552: Files or Directories Accessible to External Parties |
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) |
Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) |
Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass. |
Priority Windows may allow Command Execution via SQL Injection using an unspecified method. |
this vulnerability affect user that even not allowed to access via the web interface. First of all, the attacker needs to access the "Login menu - demo site" then he can see in this menu all the functionality of the appl...Show more |
An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which us...Show more |
1Priority Software 1Priority Enterprise Management System Nov 21, 2024 Apr 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross Site Scripting (XSS) in the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on behalf of the victim by sending a malicious URL or directing the victi...Show more |