Cipplanner / Cipace
18 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-50620 | Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage components in CIPPlanner CIPAce before 9.17.… | HIGH | 8.8 | Feb 11, 2026 |
| CVE-2024-50619 | Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privi… | HIGH | 8.8 | Feb 11, 2026 |
| CVE-2024-50618 | A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypass a protection me… | MEDIUM | 4.3 | Feb 11, 2026 |
| CVE-2024-50617 | Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authen… | HIGH | 7.5 | Feb 11, 2026 |
| CVE-2020-11586 | An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XML DTD data. | CRITICAL | 9.8 | Apr 6, 2020 |
| CVE-2020-11587 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and get the content of ETL Processes run… | HIGH | 7.5 | Apr 6, 2020 |
| CVE-2020-11588 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to two files that contain customer… | MEDIUM | 5.3 | Apr 6, 2020 |
| CVE-2020-11589 | An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET request to a cer… | HIGH | 7.5 | Apr 6, 2020 |
| CVE-2020-11590 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to HealthPage.aspx and obtain the i… | MEDIUM | 5.3 | Apr 6, 2020 |
| CVE-2020-11591 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and obtain the full application path alo… | MEDIUM | 5.3 | Apr 6, 2020 |
| CVE-2020-11592 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and get the columns of a specific table… | HIGH | 7.5 | Apr 6, 2020 |
| CVE-2020-11593 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is la… | HIGH | 7.5 | Apr 6, 2020 |
| CVE-2020-11594 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that causes a stack error to be shown pr… | HIGH | 7.5 | Apr 6, 2020 |
| CVE-2020-11595 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and obtain the upload folder path that i… | HIGH | 7.5 | Apr 6, 2020 |
| CVE-2020-11596 | A Directory Traversal issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make HTTP GET requests to a certain URL a… | HIGH | 7.5 | Apr 6, 2020 |
| CVE-2020-11597 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request and inject SQL statements in the u… | CRITICAL | 9.8 | Apr 6, 2020 |
| CVE-2020-11598 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and executing an… | CRITICAL | 9.8 | Apr 6, 2020 |
| CVE-2020-11599 | An issue was discovered in CIPPlanner CIPAce 6.80 Build 2016031401. GetDistributedPOP3 allows attackers to obtain the username and password of the SMTP user. | HIGH | 7.5 | Apr 6, 2020 |
Showing 1 to 18 of 18 CVEs