Sparkdevnetwork / Rock Rms
3 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2019-18642 | Rock RMS version before 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile update feature. The lack of validation and… | CRITICAL | 9.8 | Jan 7, 2021 |
| CVE-2019-18643 | Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a fil… | CRITICAL | 9.8 | Jan 7, 2021 |
| CVE-2019-18641 | Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller. | CRITICAL | 9.8 | Mar 20, 2020 |
Showing 1 to 3 of 3 CVEs