eharmonynew
by Synel
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-22791 | Med | 0.43 | 6.6 | 0.00 | Jan 28, 2022 | SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the system. | ||
| CVE-2022-36778 | Med | 0.42 | 6.5 | 0.00 | Sep 13, 2022 | insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code. | ||
| CVE-2022-34768 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2022 | insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code. | ||
| CVE-2021-36718 | Med | 0.40 | 6.1 | 0.01 | Dec 8, 2021 | SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name, Employee ID number, Working hours etc') The vulnerabilety has been addressed and fixed on version 11.… | ||
| CVE-2022-22790 | Med | 0.36 | 5.6 | 0.01 | Jan 28, 2022 | SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at unauthorized access to the file system. on the "Name" parameter the attacker can return to the root directory and open the host file. The path exposes… |
- risk 0.43cvss 6.6epss 0.00
SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the system.
- risk 0.42cvss 6.5epss 0.00
insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code.
- risk 0.42cvss 6.5epss 0.00
insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code.
- risk 0.40cvss 6.1epss 0.01
SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name, Employee ID number, Working hours etc') The vulnerabilety has been addressed and fixed on version 11.…
- risk 0.36cvss 5.6epss 0.01
SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at unauthorized access to the file system. on the "Name" parameter the attacker can return to the root directory and open the host file. The path exposes…