Eframework
Midasolutions · 7 CVEs
Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.
Jul 24, 2020
A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.
Jul 24, 2020
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execut…
Jul 24, 2020
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restri…
Jul 24, 2020
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE…
Jul 24, 2020
Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.
Jul 24, 2020
There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is re…
Jul 24, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-15918 | Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0. | MEDIUM | 0.56% | Jul 24, 2020 |
| CVE-2020-15919 | A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0. | MEDIUM | 0.94% | Jul 24, 2020 |
| CVE-2020-15920 | There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) pri… | CRITICAL | 98.24% | Jul 24, 2020 |
| CVE-2020-15921 | Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execu… | CRITICAL | 18.29% | Jul 24, 2020 |
| CVE-2020-15922 | There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges.… | CRITICAL | 57.33% | Jul 24, 2020 |
| CVE-2020-15923 | Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal. | HIGH | 3.31% | Jul 24, 2020 |
| CVE-2020-15924 | There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in o… | HIGH | 1.88% | Jul 24, 2020 |
Showing 1 to 7 of 7 CVEs