VYPR

Team\+ Pro

by Teamplus

CVEs (6)

  • CVE-2024-9921CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.01

    The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify and delete database contents.

  • CVE-2022-35220HigAug 2, 2022
    risk 0.50cvss 7.7epss 0.01

    Teamplus Pro community discussion function has an ‘allocation of resource without limits or throttling’ vulnerability. A remote attacker with general user privilege posting a thread with large content can cause the receiving client device to allocate too much memory, leading…

  • CVE-2022-32958HigJul 20, 2022
    risk 0.50cvss 7.7epss 0.01

    A remote attacker with general user privilege can send a message to Teamplus Pro’s chat group that exceeds message size limit, to terminate other recipients’ Teamplus Pro chat process.

  • CVE-2024-9922HigOct 14, 2024
    risk 0.49cvss 7.5epss 0.01

    The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

  • CVE-2022-35221MedAug 2, 2022
    risk 0.35cvss 5.4epss 0.01

    Teamplus Pro community discussion has an ‘allocation of resource without limits or throttling’ vulnerability on thread subject field. A remote attacker with general user privilege posting a thread subject with large content can cause the server to allocate too much memory,…

  • CVE-2024-9923MedOct 14, 2024
    risk 0.32cvss 4.9epss 0.01

    The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with administrator privileges to move arbitrary system files to the website root directory and access them.