Workforce Optimization
Verint · 6 CVEs
CVE-2024-36396
HIGH
Verint - CWE-434: Unrestricted Upload of File with Dangerous Type
Jun 13, 2024
CVE-2024-36395
MEDIUM
Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Jun 13, 2024
CVE-2021-36450
MEDIUM
Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.
Dec 15, 2021
CVE-2021-41825
MEDIUM
Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.
Oct 8, 2021
CVE-2020-23446
MEDIUM
Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API
Sep 22, 2020
CVE-2020-13480
MEDIUM
Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.
Jun 22, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-36396 | Verint - CWE-434: Unrestricted Upload of File with Dangerous Type | HIGH | 0.44% | Jun 13, 2024 |
| CVE-2024-36395 | Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | MEDIUM | 0.25% | Jun 13, 2024 |
| CVE-2021-36450 | Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter. | MEDIUM | 64.29% | Dec 15, 2021 |
| CVE-2021-41825 | Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter. | MEDIUM | 1.09% | Oct 8, 2021 |
| CVE-2020-23446 | Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API | MEDIUM | 1.24% | Sep 22, 2020 |
| CVE-2020-13480 | Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature. | MEDIUM | 0.98% | Jun 22, 2020 |
Showing 1 to 6 of 6 CVEs