VYPR

Monitool

by Badgermeter

CVEs (3)

  • CVE-2024-1302HigMar 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file obtaining all sensitive information such as database credentials.

  • CVE-2024-1303MedMar 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Incorrectly limiting the path to a restricted directory vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows an authenticated attacker to retrieve any file from the device using the download-file functionality.

  • CVE-2024-1304MedMar 12, 2024
    risk 0.41cvss 6.3epss 0.01

    Cross-site scripting vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows a remote attacker to send a specially crafted javascript payload to an authenticated user and partially hijack their browser session.