← Back

Sergestec

sergestec

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Exito
exito

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sergestec
1Exito
Oct 21, 2025
Oct 16, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Stored Cross-Site Scripting (XSS) in Sergestec's Exito v8.0, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'obs' parameter in '/admin/index.php?action=pro...Show more
Stored Cross-Site Scripting (XSS) in Sergestec's Exito v8.0, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'obs' parameter in '/admin/index.php?action=product_update'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.Show less
1Sergestec
1Exito
Oct 21, 2025
Oct 16, 2025
7.1 HIGH· v4
7.5 HIGH· v3
N/A· v2
Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker to access data belonging to other customers through the 'id' parameter in '/admin/ticket_a4.php'.
1Sergestec
1Exito
Oct 21, 2025
Oct 16, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'cat' parameter in '/public.php'.