ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-11880
CommSy through 8.6.5 has SQL Injection via the cid parameter.

CommSy through 8.6.5 has SQL Injection via the cid parameter. This is fixed in 9.2.

NVD description · AI analysis pending
7.52%
  • commsy commsy
CVE-2017-1000496
Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of service and possibly remote execution of code

Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of service and possibly remote execution of code.

NVD description · AI analysis pending
8.82%
  • commsy commsy