VYPR

EX10

by Exagrid

CVEs (3)

  • CVE-2025-29556HigJul 31, 2025
    risk 0.47cvss 7.3epss 0.00

    ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3, ExaGrid enforces restrictions preventing users with the Admin role from creating or modifying users with the Security Officer role without approval. However, a flaw in the account creation…

  • CVE-2025-29557MedJul 31, 2025
    risk 0.35cvss 5.4epss 0.00

    ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privileges can issue an HTTP request to retrieve SMTP credentials, including plaintext passwords.

  • CVE-2025-47184MedAug 21, 2025
    risk 0.34cvss 5.3epss 0.00

    An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 before 6.4.0 P20, 7.0.1 P12, and 7.2.0 P08 allows an authenticated, unprivileged attacker to achieve information disclosure and privilege escalation via a crafted ISys XML message.