DupScout Enterprise
by Flexense
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-29659 | Cri | 0.64 | 9.8 | 0.05 | Dec 9, 2020 | A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack. | ||
| CVE-2018-10566 | Med | 0.40 | 6.1 | 0.01 | May 2, 2018 | XSS exists in Flexense DupScout Enterprise from v10.0.18 to v10.7. |
- risk 0.64cvss 9.8epss 0.05
A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack.
- risk 0.40cvss 6.1epss 0.01
XSS exists in Flexense DupScout Enterprise from v10.0.18 to v10.7.