Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
i vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-37756
I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack.
I-doit I-doit
1 Github repository
10
CVSSv3
CVE-2018-1000124
I Librarian I-librarian version 4.8 and previous versions contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via p...
I-librarian I\\, Librarian
9.1
CVSSv3
CVE-2018-1000138
I, Librarian version 4.8 and previous versions contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the server to read or update internal resources.
I-librarian I Librarian
5.4
CVSSv3
CVE-2023-46003
I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php.
I-doit I-doit
1 Github repository
5.4
CVSSv3
CVE-2023-34830
i-doit Open v24 exists to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.
I-doit I-doit
1 Github repository
6.1
CVSSv3
CVE-2020-13825
A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote malicious users to inject arbitrary web script or HTML via the viewMode, tvMode, tvType, objID, catgID, objTypeID, or editMode parameter.
I-doit I-doit
9.8
CVSSv3
CVE-2019-1010248
Synetics GmbH I-doit 1.12 and previous versions is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can exploit the vulnerability by sending a malicious HTTP POST request. The fix...
I-doit I-doit
8.8
CVSSv3
CVE-2020-13826
A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an malicious user to execute arbitrary commands via a Title parameter that is mishandled in a CSV export.
I-doit I-doit
8.8
CVSSv3
CVE-2018-1000137
I, Librarian version 4.8 and previous versions contains a Cross site Request Forgery (CSRF) vulnerability in users.php that can result in the password of the admin being forced to be changed without the administrator's knowledge.
I-librarian I Librarian
6.1
CVSSv3
CVE-2018-1000139
I, Librarian version 4.8 and previous versions contains a Cross Site Scripting (XSS) vulnerability in "id" parameter in stable.php that can result in an attacker using the XSS to send a malicious script to an unsuspecting user.
I-librarian I Librarian
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22120
CVE-2024-35921
CVE-2024-35874
brute force
CVE-2024-36080
unprivileged
CVE-2024-35917
IDOR
CVE-2024-4947
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »