← Back

Systemic Rm

systemic-rm

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Risk Value
risk_value

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Systemic Rm
1Risk Value
Apr 1, 2025
Mar 18, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized...Show more
Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment or decrement the ID to access and download files they do not have permission to view.Show less
1Systemic Rm
1Risk Value
Apr 1, 2025
Mar 18, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by supplying a crafted file path, potentia...Show more
Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by supplying a crafted file path, potentially exposing sensitive information.Show less