Vulnerabilities
8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-23715 | Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download. Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download. NVD description · AI analysis pending | 8.6 | 2% | PoC |
| — | |
| CVE-2020-18668 | Cross Site Scripting (XSS) vulnerabililty in WebPort <=1.19.1 via the description parameter to script/listcalls. Cross Site Scripting (XSS) vulnerabililty in WebPort <=1.19.1 via the description parameter to script/listcalls. NVD description · AI analysis pending | 5.4 group max | <1% | PoC |
| — | |
| CVE-2020-18667 | SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn. SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2020-23659 | WebPort-v1.19.17121 is affected by Cross Site Scripting (XSS) on the "connections" feature. WebPort-v1.19.17121 is affected by Cross Site Scripting (XSS) on the "connections" feature. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2019-12461 +1 in the same advisory: …12460 | Web Port 1.19.1 allows XSS via the /log type parameter. Web Port 1.19.1 allows XSS via the /log type parameter. NVD description · AI analysis pending | 6.1 | 10% | PoC ×2 |
| — |