VYPR

TinyCheck

by Kaspersky Lab

CVEs (3)

  • CVE-2020-36199CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.02

    TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places.

  • CVE-2020-35929CriJan 19, 2021
    risk 0.64cvss 9.8epss 0.01

    In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access to remote data.

  • CVE-2020-36200MedJan 26, 2021
    risk 0.42cvss 6.5epss 0.01

    TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafted URLs.