VYPR

Espressdashboard

by Quadbase

CVEs (2)

  • CVE-2020-24985HigMar 15, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc parameter value to retrieve and execute external files or payloads.

  • CVE-2020-24982MedMar 15, 2021
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address associated with their account.