VYPR

Archer Platform

by Archer

CVEs (30)

  • CVE-2024-49208MedOct 22, 2024
    risk 0.38cvss 5.9epss 0.00

    Archer Platform 2024.03 before version 2024.08 is affected by an authorization bypass vulnerability related to supporting application files. A remote unprivileged attacker could potentially exploit this vulnerability to elevate their privileges and delete system icons.

  • CVE-2024-26311MedFeb 21, 2024
    risk 0.37cvss 5.7epss 0.01

    Archer Platform 6.x before 6.14 P2 HF1 (6.14.0.2.1) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web…

  • CVE-2023-48642MedDec 12, 2023
    risk 0.35cvss 5.4epss 0.00

    Archer Platform 6.x before 6.13 P2 (6.13.0.2) contains an authenticated HTML content injection vulnerability. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. When victim users access…

  • CVE-2023-37223MedJul 14, 2023
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows a remote authenticated attacker to execute arbitrary code via a crafted malicious script.

  • CVE-2024-34093MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Archer Platform 6 before 2024.03. There is an X-Forwarded-For Header Bypass vulnerability. An unauthenticated attacker could potentially bypass intended whitelisting when X-Forwarded-For header is enabled.

  • CVE-2024-26309MedMar 8, 2024
    risk 0.34cvss 5.3epss 0.01

    Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a sensitive information disclosure vulnerability. An unauthenticated attacker could potentially obtain access to sensitive information via an internal URL.

  • CVE-2024-41707MedJul 25, 2024
    risk 0.31cvss 4.8epss 0.00

    An issue was discovered in Archer Platform 6 before 2024.06. Authenticated users can achieve HTML content injection. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. When victim users…

  • CVE-2024-26312MedMay 6, 2024
    risk 0.28cvss 4.3epss 0.00

    Archer Platform 6 before 2024.03 contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message.

  • CVE-2024-26310MedFeb 21, 2024
    risk 0.28cvss 4.3epss 0.00

    Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated malicious user could potentially exploit this to gain access to API information that should only be accessible with extra privileges.

  • CVE-2023-45357MedOct 17, 2023
    risk 0.28cvss 4.3epss 0.00

    Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message. 6.14 (6.14.0) is also a fixed release.

Page 2 of 2