Eg Manager
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-8592 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2020 | eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password feature). | ||
| CVE-2020-8591 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2020 | eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request. | ||
| CVE-2022-29594 | Hig | 0.51 | 7.8 | 0.00 | Jun 2, 2022 | eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM. |
- risk 0.64cvss 9.8epss 0.01
eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password feature).
- risk 0.64cvss 9.8epss 0.01
eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.
- risk 0.51cvss 7.8epss 0.00
eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM.