VYPR

EDMS

by Kordil

CVEs (3)

  • CVE-2013-10066CriAug 5, 2025
    risk 0.68cvss epss 0.01

    An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an upload endpoint (users_add.php) that allows attackers to upload files to the /userpictures/ directory without authentication. This flaw enables remote code…

  • CVE-2020-13887HigJun 22, 2020
    risk 0.57cvss 8.8epss 0.02

    documents_add.php in Kordil EDMS through 2.2.60rc3 allows Remote Command Execution because .php files can be uploaded to the documents folder.

  • CVE-2020-13888MedJun 22, 2020
    risk 0.35cvss 5.4epss 0.01

    Kordil EDMS through 2.2.60rc3 allows stored XSS in users_edit.php, users_management_edit.php, and user_management.php.