VYPR

Web Reports

by Netikus

CVEs (2)

  • CVE-2026-24443HigFeb 24, 2026
    risk 0.57cvss 8.8epss 0.00

    EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the account management functionality of the Web Reports interface. The password change mechanism does not require validation of the current password before allowing a new password to…

  • CVE-2015-1180Jan 23, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Web Reports in EventSentry 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the pageId parameter to networktile/bullet.