VYPR

Portfolio

by Extensis

CVEs (5)

  • CVE-2022-24255HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.

  • CVE-2022-24254HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.03

    An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.

  • CVE-2022-24253HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.

  • CVE-2022-24252HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.02

    An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.

  • CVE-2022-24251HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.