Biscom / Secure File Transfer
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-27646 | Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft. | MEDIUM | 6.5 | Oct 22, 2020 |
| CVE-2020-8796 | Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the server. | CRITICAL | 9.8 | Feb 7, 2020 |
| CVE-2020-8503 | Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object Reference (IDOR) by an authenticated se… | MEDIUM | 6.5 | Jan 31, 2020 |
| CVE-2016-10710 | Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential numbers, which allows remote authentic… | HIGH | 8.1 | Jan 25, 2018 |
| CVE-2017-5247 | Biscom Secure File Transfer is vulnerable to cross-site scripting in the File Name field. An authenticated user with permissions to upload or send files can po… | MEDIUM | 5.4 | Jul 18, 2017 |
| CVE-2017-5246 | Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a val… | MEDIUM | 4.3 | Jul 18, 2017 |
| CVE-2017-5241 | Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024 are vulnerable to post-authentication persistent cross-site scripting (XSS) in the "Name" and "Des… | MEDIUM | 5.4 | Jun 28, 2017 |
Showing 1 to 7 of 7 CVEs