Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-48029 | Corebos 8.0 and below is vulnerable to CSV Injection. Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject a malicious command into a table. This vulnerability is exploited when an administrator visits the user management section, exports the data to a CSV file, and then opens it, leading to the execution of the malicious payload on the administrator's computer. NVD description · AI analysis pending | 8.0 | 1% | PoC |
| — | |
| CVE-2023-3069 | Unverified Password Change in GitHub repository tsolucio/corebos prior to 8. Unverified Password Change in GitHub repository tsolucio/corebos prior to 8. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2023-1527 | Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0. Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-4446 | PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0. PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2018-1000547 | coreBOS version 7.0 and earlier contains a Incorrect Access Control vulnerability in Module: coreBOS version 7.0 and earlier contains a Incorrect Access Control vulnerability in Module: Contacts that can result in The error allows you to access records that you have no permissions to. . NVD description · AI analysis pending | 5.3 | <1% |
| — |