VYPR

Omnidirectional Communication System

by Junhetec

CVEs (2)

  • CVE-2021-30173MedMay 7, 2021
    risk 0.42cvss 6.5epss 0.01

    Local File Inclusion vulnerability of the omni-directional communication system allows remote authenticated attacker inject absolute path into Url parameter and access arbitrary file.

  • CVE-2021-30172MedMay 7, 2021
    risk 0.30cvss 4.6epss 0.01

    Special characters of picture preview page in the Quan-Fang-Wei-Tong-Xun system are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out Reflected XSS (Cross-site scripting) attacks, additionally access and…