CVE Browser
CVE-2019-18642 CRITICAL
Rock RMS version before 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile update feature. The lack of validation and…
CVSS 9.8 EPSS 1.70% Jan 7, 2021
CVE-2019-18643 CRITICAL
Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a fil…
CVSS 9.8 EPSS 4.28% Jan 7, 2021
CVE-2019-18641 CRITICAL
Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller.
CVSS 9.8 EPSS 3.43% Mar 20, 2020
Showing 1 to 3 CVEs · page 1