VYPR

Vembu

by Vembu

CVEs (2)

  • CVE-2021-26474HigJun 8, 2021
    risk 0.56cvss 8.6epss 0.01

    Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.)

  • CVE-2021-43458HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths.