
vulnerabilities-cve/vulnerabilities
Releases0
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 5.3 MEDIUM | 5 MEDIUM | ||
Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with ../ (and variations), it is possible to list all the directories and check if a particular file exists. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication. | |||
| 6.1 MEDIUM | 4.3 MEDIUM | ||
Systematic IRIS Standards Management (ISM) v2.1 SP1 89 is vulnerable to unauthenticated reflected Cross Site Scripting (XSS). A user input (related to dialog information) is reflected directly in the web page, allowing a malicious user to conduct a Cross Site Scripting attack against users of the application. | |||