VYPR

Smart Wing CMS

by WISA

CVEs (2)

  • CVE-2022-23770HigOct 17, 2022
    risk 0.57cvss 8.8epss 0.01

    This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remote attackers could use this vulnerability to execute malicious commands such as directory traversal.

  • CVE-2021-26639HigAug 17, 2022
    risk 0.53cvss 8.1epss 0.00

    This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system.