VYPR

Deltaflow E Platform

by Vangene

CVEs (3)

  • CVE-2021-28173Apr 6, 2021
    risk 0.00cvss epss 0.01

    The file upload function of Vangene deltaFlow E-platform does not perform access controlled properly. Remote attackers can upload and execute arbitrary files without login.

  • CVE-2021-28172Apr 6, 2021
    risk 0.00cvss epss 0.01

    There is a Path Traversal vulnerability in the file download function of Vangene deltaFlow E-platform. Remote attackers can access credential data with this leakage.

  • CVE-2021-28171Apr 6, 2021
    risk 0.00cvss epss 0.00

    The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions remotely by tampering with users’ data in the Cookie.