VYPR

Adportal

by Ipublishmedia

CVEs (3)

  • CVE-2024-50660CriJan 7, 2025
    risk 0.64cvss 9.8epss 0.01

    File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload functionality

  • CVE-2024-50658CriJan 7, 2025
    risk 0.64cvss 9.8epss 0.01

    Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the shippingAsBilling and firstname parameters in updateuserinfo.html file

  • CVE-2024-50659MedJan 7, 2025
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privileges via the shippingAsBilling parameter in updateuserinfo.html.