ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-44837
An issue was discovered in Delta RM 1.2.

An issue was discovered in Delta RM 1.2. It is possible for an unprivileged user to access the same information as an admin user regarding the risk creation information in the /risque/administration/referentiel/json/create/categorie endpoint, using the id_cat1 query parameter to indicate the risk.

NVD description · AI analysis pending
4.3<1% PoC
  • deltarm delta rm
CVE-2021-44839
+3 in the same advisory: …44838 …44836 …44840
An issue was discovered in Delta RM 1.2.

An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user IDs that will have their passwords reset (and new ones sent to their respective e-mail addresses).

NVD description · AI analysis pending
6.5
group max
<1%
  • deltarm delta rm