VYPR

Itflow

by Itflow Org

Source repositories

CVEs (3)

  • CVE-2025-67081MedJan 15, 2026
    risk 0.32cvss 4.9epss 0.00

    An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a profile. An attacker with admin account can exploit this issue via blind SQL injection, allowing for the extraction of arbitrary data from the database. The…

  • CVE-2026-47755MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the…

  • CVE-2024-25344MedFeb 26, 2024
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to execute arbitrary code and obtain sensitive information via the settings.php, settings+company.php, settings_defaults.php,settings_integrations.ph…