VYPR

LogRhythm

by LogRhythm

CVEs (2)

  • CVE-2020-25096HigDec 17, 2020
    risk 0.57cvss 8.8epss 0.01

    LogRhythm Platform Manager (PM) 7.4.9 has Incorrect Access Control. Users within LogRhythm can be delegated different roles and privileges, intended to limit what data and services they can interact with. However, no access control is enforced for WebSocket-based communication…

  • CVE-2021-41943MedDec 13, 2022
    risk 0.40cvss 6.1epss 0.00

    Logrhythm Web Console 7.4.9 allows for HTML tag injection through Contextualize Action -> Create a new Contextualize Action -> Inject your HTML tag in the name field.