VYPR

CentreStack

by CentreStack

CVEs (8)

  • CVE-2024-37782CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.

  • CVE-2024-37783MedNov 22, 2024
    risk 0.35cvss 5.4epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the sessionId parameter at /portal/ForgotPassword.aspx.

  • CVE-2026-54368HigJul 30, 2026
    risk 0.00cvss 8.8epss 0.00

    CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsondir API endpoint. Attackers…

  • CVE-2026-54367HigJul 30, 2026
    risk 0.00cvss 8.6epss 0.00

    CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can generate valid encrypted EntAcctId…

  • CVE-2026-54366HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage configuration handler. Attackers can send a crafted request to the…

  • CVE-2026-54365HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a…

  • CVE-2026-54364MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into a crafted AccountName parameter posted to the SelectProvider.aspx endpoint.…

  • CVE-2026-54363CriJul 30, 2026
    risk 0.00cvss 9.1epss 0.00

    CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt() across all…