VYPR

Cdsoft

by Cdsoft

CVEs (2)

  • CVE-2022-27247MedMay 13, 2022
    risk 0.35cvss 5.3epss 0.01

    onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth, full address, mail information, and phone number) via GastKont Insecure Direct Object Reference.

  • CVE-2014-5737Sep 9, 2014
    risk 0.00cvss epss 0.00

    The CDsoft (aka com.wCDSOFT) application 0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.