vulnerabilities-cve/vulnerabilities

vulnerabilities-cve/vulnerabilities

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
5.3 MEDIUM5 MEDIUM

Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with ../ (and variations), it is possible to list all the directories and check if a particular file exists.

9.8 CRITICAL7.5 HIGH

Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication.

6.1 MEDIUM4.3 MEDIUM

Systematic IRIS Standards Management (ISM) v2.1 SP1 89 is vulnerable to unauthenticated reflected Cross Site Scripting (XSS). A user input (related to dialog information) is reflected directly in the web page, allowing a malicious user to conduct a Cross Site Scripting attack against users of the application.