VYPR

Rpage

by Heimavista

CVEs (2)

  • CVE-2022-39053MedSep 28, 2022
    risk 0.40cvss 6.1epss 0.01

    Heimavista Rpage has insufficient filtering for platform web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.

  • CVE-2024-2412MedMar 13, 2024
    risk 0.34cvss 5.3epss 0.00

    The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on sites where user registration is supposed to be disabled.