VYPR

Groupware

by handysoft

CVEs (2)

  • CVE-2021-26630HigMay 19, 2022
    risk 0.51cvss 7.8epss 0.01

    Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files. This vulnerability can be exploited by using the file download or execution path as the parameter value of the vulnerable function.

  • CVE-2020-7804MedApr 29, 2020
    risk 0.42cvss 6.4epss 0.01

    ActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary command via the ShellExec method.