ZeroHour

Vulnerabilities

10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-7667
Prima Systems FlexAir, Versions 2.3.38 and prior.

Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable name, and an attacker can use brute force to identify the database backup file name. A malicious actor can exploit this issue to download the database file and disclose login information, which can allow the attacker to bypass authentication and have full access to the system.

NVD description · AI analysis pending
9.8
group max
4% PoC
  • primasystems flexair
CVE-2019-7671
+2 in the same advisory: …9189 …7672
Prima Systems FlexAir, Versions 2.3.38 and prior.

Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.

NVD description · AI analysis pending
9.0
group max
8% PoC
  • primasystems flexair